First published: Tue Sep 17 2019(Updated: )
IBM WebSphere Application Server could allow a user with access to audit logs to obtain sensitive information, caused by improper handling of command line options.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server | >=7.0.0.0<=7.0.0.45 | |
IBM WebSphere Application Server | >=8.0.0.0<=8.0.0.15 | |
IBM WebSphere Application Server | >=8.5.0.0<=8.5.5.16 | |
IBM WebSphere Application Server | >=9.0.0.0<=9.0.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4477 is classified as medium, indicating a moderate risk of information exposure.
CVE-2019-4477 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0.
To fix CVE-2019-4477, apply the appropriate patches or updates provided by IBM for your WebSphere Application Server version.
CVE-2019-4477 can allow unauthorized users with access to audit logs to obtain sensitive information related to the application.
Currently, it is recommended to restrict access to audit logs as a temporary mitigation for CVE-2019-4477.