PT-2020-18173 · Ibm · Ibm Websphere Application Server

Published

2020-09-30

·

Updated

2020-10-02

·

CVE-2020-4629

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server versions 7.0 through 9.0
Description The issue allows a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system.
Recommendations For IBM WebSphere Application Server versions 7.0 through 9.0, consider restricting access to detailed technical error messages to minimize the risk of exploitation. As a temporary workaround, limit the information disclosed in error messages until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4629

Affected Products

Ibm Websphere Application Server