Information disclosure in IBM WebSphere Application Server - CVE-2011-4343

 

Information disclosure in IBM WebSphere Application Server - CVE-2011-4343

Published: October 31, 2017


Vulnerability identifier: #VU9019
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-4343
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain sensitive information.

The weakness exists due to an error in Apache MyFaces. A remote attacker can use specially crafted parameters to inject EL expressions into input fields mapped as view parameters and obtain sensitive information.

Affected software

IBM WebSphere Application Server

How to mitigate CVE-2011-4343

Update to version 8.0.0.15 or 8.5.5.13.


External References

Related Security Bulletins