IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3, when the installation lacks a default error page, allows remote attackers to obtain sensitive information by triggering an exception.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/93143 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21981529 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI54459 | vendor advisory broken link |