CVE-2015-0178: Infoleak
Published Mar 18, 2015
·Updated
The Java overlay feature in IBM Bluemix Liberty before 1.13-20150209-1122 for Java does not properly support WAR applications, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected Software
2 affected components
IBM Liberty Java<=1.12-20150130-1059
IBM Bluemix
Event History
Mar 18, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0178?
CVE-2015-0178 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2015-0178?
To fix CVE-2015-0178, upgrade IBM Bluemix Liberty to version 1.13-20150209-1122 or later.
3
What applications are affected by CVE-2015-0178?
CVE-2015-0178 affects WAR applications deployed in IBM Bluemix Liberty versions prior to 1.13-20150209-1122.
4
Can CVE-2015-0178 lead to data exposure?
Yes, CVE-2015-0178 could allow remote attackers to obtain sensitive information from affected applications.
5
Is there a workaround for CVE-2015-0178?
There are no known effective workarounds for CVE-2015-0178; upgrading to the fixed version is recommended.