CVE-2013-2951: High severity IBM WebSphere Portal vulnerability
IBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for the Selfcare Portlet (Profile Management), which allows local users to obtain sensitive information by reading the file. IBM X-Force ID: 83621.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2951?
CVE-2013-2951 has a low to medium severity rating due to the potential exposure of sensitive information.
How do I fix CVE-2013-2951?
To fix CVE-2013-2951, disable tracing for the Selfcare Portlet or apply the latest security patches provided by IBM.
Who is affected by CVE-2013-2951?
CVE-2013-2951 affects users of IBM WebSphere Portal versions 7.0.0.x and 8.0.0.x that have tracing enabled.
What information is exposed by CVE-2013-2951?
CVE-2013-2951 exposes sensitive user passwords written to a trace file when tracing is enabled.
Can local users exploit CVE-2013-2951?
Yes, local users can exploit CVE-2013-2951 by accessing the trace file to obtain sensitive information.