2.1

CVE-2008-7261

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-010 records DEBUG messages containing user credentials in the log4j.xml file, which might allow local users to obtain sensitive information by reading this file.

Data is provided by the National Vulnerability Database (NVD)
IbmFilenet P8 Application Engine Version3.5.1 Update001
IbmFilenet P8 Application Engine Version3.5.1 Update002
IbmFilenet P8 Application Engine Version3.5.1 Update003
IbmFilenet P8 Application Engine Version3.5.1 Update004
IbmFilenet P8 Application Engine Version3.5.1 Update005
IbmFilenet P8 Application Engine Version3.5.1 Update006
IbmFilenet P8 Application Engine Version3.5.1 Update007
IbmFilenet P8 Application Engine Version3.5.1 Update008
IbmFilenet P8 Application Engine Version3.5.1 Update009
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.128
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N