IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 02:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1PI38403 - | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg21963275 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/76466 - | |
References | () http://www.securitytracker.com/id/1033325 - |
Information
Published : 2015-08-22 23:59
Updated : 2024-11-21 02:26
NVD link : CVE-2015-1932
Mitre link : CVE-2015-1932
CVE.ORG link : CVE-2015-1932
JSON object : View
Products Affected
ibm
- websphere_application_server
- websphere_virtual_enterprise
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor