---------------------------------------------------------------------- Secunia integrated with Microsoft WSUS http://secunia.com/blog/71/ ---------------------------------------------------------------------- TITLE: WebSphere Application Server "Requires SSL" Option Security Issue SECUNIA ADVISORY ID: SA38425 VERIFY ADVISORY: http://secunia.com/advisories/38425/ DESCRIPTION: A security issue has been reported in WebSphere Application Server, which can potentially lead to disclosure of sensitive information. The security issue is caused due to an error in the handling of configuration data, which can lead to the "Requires SSL" option for Single Sign-on (SSO) not being detected and applied as expected. The security issue is reported in IBM WebSphere Application Server versions 7.0.0.0 through 7.0.0.8. SOLUTION: Apply Interim Fix APAR PM00610 (please see the vendor's advisory for more information). PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: IBM (PM00610): http://www-01.ibm.com/support/docview.wss?uid=swg21417839 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------