The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www-1.ibm.com/support/docview.wss?uid=swg1PK67405 | vendor advisory |
http://www.securityfocus.com/bid/33849 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/48527 | vdb entry |