Vulnerable Systems:
* IBM Tivoli Monitoring 6.2.3 and 6.2.3.1
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
IBM Tivoli Monitoring and HTTP Server contain a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an error occurs during the use of the HTTP TRACE and TRACK methods. This may allow a remote attacker to gain access to potentially sensitive information.
Technical:
The concering the generally known problems with the TRACK and TRACE methods. The 'information disclosure' aspect is frequently used in conjunction with XSS attacks for example, as the disclosure of session information is a primary goal of such attacks.
Disclosure Timeline:
Published: Oct 22 2012 12:00AM
Updated: Oct 22 2012 12:00AM