Information disclosure in WebSphere Portal - CVE-2017-1698
Published: December 22, 2017 / Updated: December 25, 2017
WebSphere Portal
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The weakness exists due to unspecified condition that exist when returning an error message. A remote attacker can send a specially crafted request, trigger an error message response and access sensitive information within the error message.
Successful exploitation of the vulnerability may result in further attacks.