Information Exposure Through an Error Message in IBM WebSphere Application Server - CVE-2019-4441

 

Information Exposure Through an Error Message in IBM WebSphere Application Server - CVE-2019-4441

Published: June 13, 2023


Vulnerability identifier: #VU77193
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-4441
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability occurs when a stack trace is returned in the browser. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

IBM WebSphere Application Server
IBM Cloud Transformation Advisor
IBM CICS TX on Cloud
Watson Speech Services

How to mitigate CVE-2019-4441

Install updates from vendor's website.

IBM Cloud Transformation Advisor - update to 2.0.3
Watson Speech Services - update to 1.1.1
IBM CICS TX on Cloud - update to 10.1.0.0 SpecialFIX 032020

External References

Related Security Bulletins