IBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for the Selfcare Portlet (Profile Management), which allows local users to obtain sensitive information by reading the file. IBM X-Force ID: 83621.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Websphere_portal | Ibm | 7.0.0.0 (including) | 7.0.0.0 (including) |
Websphere_portal | Ibm | 7.0.0.1 (including) | 7.0.0.1 (including) |
Websphere_portal | Ibm | 7.0.0.2 (including) | 7.0.0.2 (including) |
Websphere_portal | Ibm | 8.0.0.0 (including) | 8.0.0.0 (including) |
Websphere_portal | Ibm | 8.0.0.1 (including) | 8.0.0.1 (including) |