CVE-2018-1621: Medium severity ibm websphere application server feature pack for web services vulnerability
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local attacker to obtain clear text password in a trace file caused by improper handling of some datasource custom properties. IBM X-Force ID: 144346.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1621?
CVE-2018-1621 is rated as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2018-1621?
To mitigate CVE-2018-1621, update your IBM WebSphere Application Server to a patched version that addresses the handling of datasource custom properties.
Who is affected by CVE-2018-1621?
CVE-2018-1621 affects local users of IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 who can access trace files.
What types of attacks can exploit CVE-2018-1621?
CVE-2018-1621 can be exploited by local attackers who gain access to trace files to obtain clear text passwords.
Is there a workaround for CVE-2018-1621?
As a temporary workaround for CVE-2018-1621, restrict access to trace files and review datasource configurations to limit exposure.