Information disclosure in IBM WebSphere Application Server Liberty - CVE-2016-0378
Published: October 23, 2023
Vulnerability identifier: #VU82297
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0378
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
IBM WebSphere Application Server Liberty
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
How to mitigate CVE-2016-0378
Install updates from vendor's website.
IBM WebSphere Application Server Liberty - update to 16.0.0.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4