IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.1 CF14, and 8.5.0 through 8.5.0.0 CF02 allows remote authenticated users to discover credentials by reading HTML source code.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1PI22104 | vendor advisory |
http://secunia.com/advisories/61126 | third party advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21684652 | patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/94658 | vdb entry |