Information disclosure in IBM WebSphere Application Server - CVE-2023-50315

 

Information disclosure in IBM WebSphere Application Server - CVE-2023-50315

Published: August 15, 2024


Vulnerability identifier: #VU96059
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50315
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote attacker can use a certificate issued by a trusted authority to obtain sensitive information.


Affected software

IBM WebSphere Application Server
IBM Business Automation Workflow
IBM Tivoli System Automation Application Manager
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Maximo Asset Management
WebSphere Service Registry and Repository
IBM Rational ClearQuest
IBM Tivoli Monitoring
IBM Security Verify Governance
IBM Cloud Pak System
Tivoli Composite Application Manager for Application Diagnostics
Business Monitor

How to mitigate CVE-2023-50315

Install updates from vendor's website.

IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Security Verify Governance - update to 10.0.2.0.4

External References

Related Security Bulletins