Information disclosure in IBM WebSphere Application Server - CVE-2017-1382

 

Information disclosure in IBM WebSphere Application Server - CVE-2017-1382

Published: July 31, 2017


Vulnerability identifier: #VU7605
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-1382
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vendor: IBM Corporation
Affected software:
IBM WebSphere Application Server

Detailed vulnerability description

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability is due to improper security restrictions imposed by the affected software. A local attacker can cause the application to set insecure file permissions after running custom startup scripts and gain access to sensitive information, such as log files on the targeted system.

Successful exploitation of the vulnerability results in information disclosure.


How to mitigate CVE-2017-1382

Update 7.0.x to version 7.0.0.45 or later.
Update 8.0.x to version 8.0.0.14 or later.
Update 8.5.x to version 8.5.5.12 or later.
Update 9.0.x to version 9.0.0.5 or later.

Sources