Information disclosure in IBM WebSphere Application Server - CVE-2017-1382
Published: July 31, 2017
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability is due to improper security restrictions imposed by the affected software. A local attacker can cause the application to set insecure file permissions after running custom startup scripts and gain access to sensitive information, such as log files on the targeted system.
Successful exploitation of the vulnerability results in information disclosure.
Affected software
How to mitigate CVE-2017-1382
Update 8.0.x to version 8.0.0.14 or later.
Update 8.5.x to version 8.5.5.12 or later.
Update 9.0.x to version 9.0.0.5 or later.