Information disclosure in IBM WebSphere Application Server - CVE-2017-1743
Published: May 10, 2018 / Updated: May 11, 2018
Vulnerability identifier: #VU12527
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1743
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.
The weakness exists due to a flaw in the handling of Administrative Console panel fields. A remote attacker can gain access to potentially sensitive information.
Affected software
IBM WebSphere Application Server
IBM Tivoli System Automation Application Manager
IBM Tivoli System Automation Application Manager
How to mitigate CVE-2017-1743
Install update from vendor's website.