>> IBM WebSphere Application Server Security Bypass and DoS Issues
Title : IBM WebSphere Application Server Security Bypass and DoS Issues VUPEN ID : VUPEN/ADV-2007-3955 CVE ID : CVE-2007-3847 - CVE-2007-6679
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-11-22
Technical Description
Multiple vulnerabilities have been identified in IBM WebSphere Application Server, which could be exploited by attackers to bypass security restrictions or cause a denial of service.
The first issue is caused by unspecified security concerns with monitor role users in the Administrative Console component.
The second vulnerability is caused by an error in the IBM HTTP Server component. For additional information, see : VUPEN/ADV-2007-3020