PT-2018-15013 · Ibm · Ibm Websphere Application Server

Published

2018-12-10

·

Updated

2019-10-09

·

CVE-2018-1957

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server version 9
Description The issue is caused by the mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. This could allow sensitive information to be available.
Recommendations For IBM WebSphere Application Server version 9, consider restricting access to unprotected URIs until a fix is available. As a temporary workaround, review the application's handling of the httpServletRequest#authenticate() API return values to prevent sensitive information disclosure.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1957

Affected Products

Ibm Websphere Application Server