Information disclosure in IBM WebSphere Commerce and IBM WebSphere Application Server - CVE-2016-5986

 

Information disclosure in IBM WebSphere Commerce and IBM WebSphere Application Server - CVE-2016-5986

Published: September 19, 2016 / Updated: September 19, 2016


Vulnerability identifier: #VU531
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5986
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to obtain potentially sensitive information on the target system.
The weakness exists due to response handling error that may cause sensitive data disclosure by a malicious user.
Successful exploitation of the vulnerability results in access to potentially sensitive data on the vulnerable system.

Affected software

IBM WebSphere Commerce
IBM WebSphere Application Server
Virtualization Engine TS7700 3957-V07
Virtualization Engine TS7700 3957-VEB
Virtualization Engine TS7700 3957-VEC

How to mitigate CVE-2016-5986

Update to APAR PI67093.

Virtualization Engine TS7700 3957-V07 - update to 8.33.1.11
Virtualization Engine TS7700 3957-VEB - update to 8.33.1.11
Virtualization Engine TS7700 3957-VEC - update to 8.40.0.71

External References

Related Security Bulletins