Information disclosure in IBM WebSphere Application Server Liberty - CVE-2016-0378

 

Information disclosure in IBM WebSphere Application Server Liberty - CVE-2016-0378

Published: October 23, 2023


Vulnerability identifier: #VU82297
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0378
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

IBM WebSphere Application Server Liberty
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data

How to mitigate CVE-2016-0378

Install updates from vendor's website.

IBM WebSphere Application Server Liberty - update to 16.0.0.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4

External References

Related Security Bulletins