IBM Affected

Notified:  March 20, 2001 Updated: August 23, 2001

Status

Affected

Vendor Statement

IBM has fixed this vulnerability in WebSphere, and has a fix available to customers. The location of the fix is given in "III. Solution" of this Note. IBM does not support versions of WebSphere earlier than 3.02, so no fix is available for versions prior to 3.02. We urge customers who employ affected versions of WebSphere to download and apply the fix described in this note as soon as possible to reduce their security exposure.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.