First published: Fri Jul 05 2019(Updated: )
An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATH_INFO to swp/login/EJBRemoteService/, related to com.swift.ejbgwt.j2ee.client.EjBlnvocationException error log information containing null@java:comp/env/ error messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SWIFT Alliance Web Platform | =7.1.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-16386 is high with a score of 7.5.
The SWIFT Alliance Web Platform version 7.1.23 is affected by CVE-2018-16386.
The CWE ID of CVE-2018-16386 is 116.
An attacker can achieve log injection and arbitrary log filename by manipulating the PATH_INFO to swp/login/EJBRemoteService/.
Currently, there is no specific fix available for CVE-2018-16386, it is advised to follow the recommendations provided by the software vendor or CERT/CSIRT.