CVE Vulnerabilities

CVE-2008-7261

Published: Sep 20, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-010 records DEBUG messages containing user credentials in the log4j.xml file, which might allow local users to obtain sensitive information by reading this file.

Affected Software

NameVendorStart VersionEnd Version
Filenet_p8_application_engineIbm3.5.1 (including)3.5.1 (including)
Filenet_p8_application_engineIbm3.5.1-001 (including)3.5.1-001 (including)
Filenet_p8_application_engineIbm3.5.1-002 (including)3.5.1-002 (including)
Filenet_p8_application_engineIbm3.5.1-003 (including)3.5.1-003 (including)
Filenet_p8_application_engineIbm3.5.1-004 (including)3.5.1-004 (including)
Filenet_p8_application_engineIbm3.5.1-005 (including)3.5.1-005 (including)
Filenet_p8_application_engineIbm3.5.1-006 (including)3.5.1-006 (including)
Filenet_p8_application_engineIbm3.5.1-007 (including)3.5.1-007 (including)
Filenet_p8_application_engineIbm3.5.1-008 (including)3.5.1-008 (including)
Filenet_p8_application_engineIbm3.5.1-009 (including)3.5.1-009 (including)

References