CVE Vulnerabilities

CVE-2013-2951

Published: Jul 11, 2018 | Modified: Sep 06, 2018
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for the Selfcare Portlet (Profile Management), which allows local users to obtain sensitive information by reading the file. IBM X-Force ID: 83621.

Affected Software

Name Vendor Start Version End Version
Websphere_portal Ibm 7.0.0.0 (including) 7.0.0.0 (including)
Websphere_portal Ibm 7.0.0.1 (including) 7.0.0.1 (including)
Websphere_portal Ibm 7.0.0.2 (including) 7.0.0.2 (including)
Websphere_portal Ibm 8.0.0.0 (including) 8.0.0.0 (including)
Websphere_portal Ibm 8.0.0.1 (including) 8.0.0.1 (including)

References