The Unified Task List (UTL) Portlet for IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 allows remote attackers to obtain potentially sensitive information about environment variables and JAR versions via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/60499 | third party advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21677032 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/93530 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI18909 | vendor advisory |