IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain sensitive information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21990056 | patch vendor advisory |
http://www.securityfocus.com/bid/93013 | vdb entry |
http://www.securitytracker.com/id/1036838 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI67093 | not applicable vendor advisory |