CVE-2011-1310Sensitive Information Exposure in IBM Websphere Application Server

Severity
1.9LOWNVD
EPSS
0.1%
top 84.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 8
Latest updateMay 17

Description

The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which allows local users to obtain potentially sensitive information by reading these files.

CVSS vector

AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-46q9-wmx8-j59x: The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 62022-05-17
CVEList
CVE-2011-1310: The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 62011-03-08
CVE-2011-1310 — Sensitive Information Exposure in IBM | cvebase