IBM HTTP Server "httpOnly" Cookie Disclosure and Scoreboard

by Carol~ Moderator - 3/19/12 3:04 PM

In Reply to: VULNERABILITIES / FIXES - March 19, 2012 by Carol~ Moderator

IBM HTTP Server "httpOnly" Cookie Disclosure and Scoreboard Security Bypass

Release Date : 2012-03-19

Criticality level : Less critical
Impact : Security Bypass
Exposure of sensitive information
Where : From remote
Solution Status : Vendor Patch

Software: IBM HTTP Server 7.0.x
IBM HTTP Server 8.0.x

Description:
IBM has acknowledged a weakness and a vulnerability in IBM HTTP Server, which can be exploited by malicious people to disclose potentially sensitive information and bypass certain security restrictions.

The weakness and the vulnerability are reported in versions 7.0 and 8.0.

Solution:
Apply APAR PM55760 and PM56128. A fix is scheduled for versions 7.0.0.23 and 8.0.0.3.

Original Advisory:
IBM (PM55760, PM56128):
http://www.ibm.com/support/docview.wss?uid=swg1PM55760
http://www.ibm.com/support/docview.wss?uid=swg1PM56128

http://secunia.com/advisories/48386/