CVE-2018-16386: High severity swift alliance web platform vulnerability
An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATHINFO to swp/login/EJBRemoteService/, related to com.swift.ejbgwt.j2ee.client.EjBlnvocationException error log information containing null@java:comp/env/ error messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16386?
The severity of CVE-2018-16386 is high with a score of 7.5.
What software is affected by CVE-2018-16386?
The SWIFT Alliance Web Platform version 7.1.23 is affected by CVE-2018-16386.
What is the CWE ID of CVE-2018-16386?
The CWE ID of CVE-2018-16386 is 116.
How can the log injection vulnerability be exploited in CVE-2018-16386?
An attacker can achieve log injection and arbitrary log filename by manipulating the PATH_INFO to swp/login/EJBRemoteService/.
Is there a fix available for CVE-2018-16386?
Currently, there is no specific fix available for CVE-2018-16386, it is advised to follow the recommendations provided by the software vendor or CERT/CSIRT.