Mailing List

Name:

Email:

[SingCERT] IBM WebSphere Application Server 'logoutExitPage' Parameter Security Bypass Vulnerability

Attention: open in a new window. PDFPrintE-mail

[ Summary ]

IBM WebSphere Application Server is prone to a security-bypass vulnerability because it fails to properly validate the 'logoutExitPage' parameter. An attacker can exploit this issue to redirect to a domain that should be blocked.

[ Affected Systems ]

IBM WebSphere Application Server 6.1 and 7.0 are vulnerable; other versions may also be affected.

[ Impact Analysis ]

Successful exploits may allow attackers to bypass certain security restrictions, which may lead to other attacks.

[ Solution/Workaround ]

The vendor has released a fix.

http://www-01.ibm.com/support/docview.wss?uid=swg1PM42436

[ Reference ]

http://xforce.iss.net/xforce/xfdb/68570