CVE-2014-0823: Infoleak
IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote attackers to read arbitrary files via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0823?
CVE-2014-0823 has a severity rating that may depend on the specific configuration and environment of the IBM WebSphere Application Server but is generally considered critical due to its ability to allow remote access to sensitive files.
How do I fix CVE-2014-0823?
To fix CVE-2014-0823, you should upgrade your IBM WebSphere Application Server to version 8.0.0.9 or 8.5.5.2 or later.
Who is affected by CVE-2014-0823?
CVE-2014-0823 affects IBM WebSphere Application Server versions 7.0, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2.
What can attackers do with CVE-2014-0823?
Attackers exploiting CVE-2014-0823 can read arbitrary files from the IBM WebSphere Application Server through crafted URLs, potentially exposing sensitive data.
Is there a workaround for CVE-2014-0823?
While upgrading is the primary solution, temporarily restricting access to the web server or implementing additional network security measures may help mitigate the risk of CVE-2014-0823.