CVE-2017-1381: Infoleak
Published Jul 21, 2017
·Updated
IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152.
Affected Software
4 affected components
IBM WebSphere Application Server Feature Pack for Web Services>=7.0.0.0<=7.0.0.43
IBM WebSphere Application Server Feature Pack for Web Services>=8.0.0.0<=8.0.0.13
IBM WebSphere Application Server Feature Pack for Web Services>=8.5.0.0<=8.5.5.12
IBM WebSphere Application Server Feature Pack for Web Services>=9.0.0.0<=9.0.0.4
Remediation
Patch Available
Event History
Jul 21, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1381?
CVE-2017-1381 has a medium severity level as it allows local attackers to obtain sensitive information.
2
How do I fix CVE-2017-1381?
To fix CVE-2017-1381, upgrade to the latest version of IBM WebSphere Application Server that addresses this vulnerability.
3
Which versions of IBM WebSphere Application Server are affected by CVE-2017-1381?
CVE-2017-1381 affects versions 7.0, 8.0, 8.5, and 9.0 of IBM WebSphere Application Server.
4
What type of attack does CVE-2017-1381 involve?
CVE-2017-1381 involves a local attack exploiting stale data being cached and served.
5
Is there a workaround for CVE-2017-1381?
There are no specific workarounds for CVE-2017-1381; upgrading to an unaffected version is recommended.