First published: Wed Jul 11 2018(Updated: )
IBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for the Selfcare Portlet (Profile Management), which allows local users to obtain sensitive information by reading the file. IBM X-Force ID: 83621.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =7.0.0.0 | |
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =8.0.0.0 | |
IBM WebSphere Portal | =8.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2951 has a low to medium severity rating due to the potential exposure of sensitive information.
To fix CVE-2013-2951, disable tracing for the Selfcare Portlet or apply the latest security patches provided by IBM.
CVE-2013-2951 affects users of IBM WebSphere Portal versions 7.0.0.x and 8.0.0.x that have tracing enabled.
CVE-2013-2951 exposes sensitive user passwords written to a trace file when tracing is enabled.
Yes, local users can exploit CVE-2013-2951 by accessing the trace file to obtain sensitive information.