Information Disclosure Vulnerability in IBM WebSphere Portal Products
CVE-2013-2951

7.8HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
11 July 2018

What is CVE-2013-2951?

IBM WebSphere Portal versions 7.0.0.x and 8.0.0.x are susceptible to a security concern where passwords are inadvertently written to a trace file when tracing is activated for the Selfcare Portlet (Profile Management). This flaw enables local users to access sensitive data by reading the contents of the trace file, potentially exposing user credentials and other sensitive information. Organizations utilizing these versions should take immediate steps to mitigate this risk and ensure secure handling of sensitive data.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.