CVE-2014-0857: Infoleak
The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0857?
CVE-2014-0857 is classified as a medium severity vulnerability.
How do I fix CVE-2014-0857?
To fix CVE-2014-0857, you should upgrade to IBM WebSphere Application Server versions 8.0.0.9, 8.5.5.2 or later.
What type of information can be disclosed by exploiting CVE-2014-0857?
Exploiting CVE-2014-0857 can allow remote authenticated users to obtain sensitive information from the Administrative Console.
Which versions of IBM WebSphere Application Server are affected by CVE-2014-0857?
CVE-2014-0857 affects IBM WebSphere Application Server versions 7.0, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2.
Is my WebSphere Application Server vulnerable due to CVE-2014-0857 if I am using an updated version?
If you are using IBM WebSphere Application Server versions after 8.0.0.9 or 8.5.5.2, your system is not vulnerable to CVE-2014-0857.