Information Exposure Through an Error Message in IBM WebSphere Application Server - CVE-2019-4441
Published: June 13, 2023
Vulnerability identifier: #VU77193
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-4441
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability occurs when a stack trace is returned in the browser. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
IBM WebSphere Application Server
IBM Cloud Transformation Advisor
IBM CICS TX on Cloud
Watson Speech Services
IBM Cloud Transformation Advisor
IBM CICS TX on Cloud
Watson Speech Services
How to mitigate CVE-2019-4441
Install updates from vendor's website.
IBM Cloud Transformation Advisor - update to 2.0.3
Watson Speech Services - update to 1.1.1
IBM CICS TX on Cloud - update to 10.1.0.0 SpecialFIX 032020
Watson Speech Services - update to 1.1.1
IBM CICS TX on Cloud - update to 10.1.0.0 SpecialFIX 032020