Information Disclosure Vulnerability in IBM WebSphere Application Server
CVE-2017-1583
7.5HIGH
Summary
An information disclosure vulnerability exists in IBM WebSphere Application Server due to improper error handling utilized by MyFaces in JSF. This weakness may allow remote attackers to exploit the system and gain access to sensitive information, which could lead to further attacks or data exposure. Organizations using affected versions should review their configurations and apply appropriate patches to mitigate potential risks.
Affected Version(s)
Liberty for Java for Bluemix 3.13
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved