PT-2018-15013 · Ibm · Ibm Websphere Application Server

Publicado

2018-12-10

·

Atualizado

2019-10-09

·

CVE-2018-1957

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server version 9
Description The issue is caused by the mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. This could allow sensitive information to be available.
Recommendations For IBM WebSphere Application Server version 9, consider restricting access to unprotected URIs until a fix is available. As a temporary workaround, review the application's handling of the httpServletRequest#authenticate() API return values to prevent sensitive information disclosure.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1957

Produtos afetados

Ibm Websphere Application Server