CVE-2019-4441: Medium severity ibm websphere application server feature pack for web services vulnerability
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 163177.
Other sources
IBM WebSphere Application Server could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4441?
CVE-2019-4441 is classified as a moderate severity vulnerability because it could allow a remote attacker to access sensitive information.
How do I fix CVE-2019-4441?
To mitigate CVE-2019-4441, apply the relevant patches or updates provided by IBM for affected versions of WebSphere Application Server.
Which versions of IBM WebSphere Application Server are affected by CVE-2019-4441?
CVE-2019-4441 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, 9.0, and Liberty up to version 19.0.0.11.
Can CVE-2019-4441 lead to data leakage?
Yes, CVE-2019-4441 could lead to data leakage as it allows attackers to obtain sensitive information through stack traces.
Is a workaround available for CVE-2019-4441?
IBM has not publicly announced specific workarounds for CVE-2019-4441, so applying the available patches is recommended.