Re: IBM AS/400 HTTP Server '/' attack

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



According to a source from IBM,

   1. It is the WebSphere version 3.5.4 of the File Serving Servlet 
      that is vulnerable, not the web server.

   2. A fix is to be available in fixpack 5 due at end of November.

Thomas


> I can confirm that a server reporting 'IBM-HTTP-Server/1.0' _IS_ vulrable
> to this. I do not know if updates increment that number or not...
 
------------------------------------------------------------
Thomas Reinke                            Tel: (905) 331-2260
Director of Technology                   Fax: (905) 331-2504
E-Soft Inc.                         http://www.e-softinc.com
Publishers of SecuritySpace     http://www.securityspace.com

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux