Information disclosure in IBM WebSphere Application Server - CVE-2017-1382

 

Information disclosure in IBM WebSphere Application Server - CVE-2017-1382

Published: July 31, 2017


Vulnerability identifier: #VU7605
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1382
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability is due to improper security restrictions imposed by the affected software. A local attacker can cause the application to set insecure file permissions after running custom startup scripts and gain access to sensitive information, such as log files on the targeted system.

Successful exploitation of the vulnerability results in information disclosure.


Affected software

IBM WebSphere Application Server

How to mitigate CVE-2017-1382

Update 7.0.x to version 7.0.0.45 or later.
Update 8.0.x to version 8.0.0.14 or later.
Update 8.5.x to version 8.5.5.12 or later.
Update 9.0.x to version 9.0.0.5 or later.


External References

Related Security Bulletins