CVE-2014-0891Sensitive Information Exposure in IBM Websphere Application Server

Severity
5.0MEDIUMNVD
EPSS
0.4%
top 39.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 28
Latest updateMay 17

Description

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information by leveraging incorrect request handling by the (1) Proxy or (2) ODR server.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f59j-r5m6-q89x: IBM WebSphere Application Server (WAS) 72022-05-17
CVEList
CVE-2014-0891: IBM WebSphere Application Server (WAS) 72014-06-28
CVE-2014-0891 — Sensitive Information Exposure in IBM | cvebase