5

CVE-2010-2323

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS might allow attackers to obtain sensitive information by reading the default_create.log file that is associated with profile creation by the BBOWWPFx job and the zPMT.

Data is provided by the National Vulnerability Database (NVD)
IbmWebsphere Application Server Version <= 7.0.0.10
   IbmZos
IbmWebsphere Application Server Version7.0
   IbmZos
IbmWebsphere Application Server Version7.0.0.1
   IbmZos
IbmWebsphere Application Server Version7.0.0.2
   IbmZos
IbmWebsphere Application Server Version7.0.0.3
   IbmZos
IbmWebsphere Application Server Version7.0.0.4
   IbmZos
IbmWebsphere Application Server Version7.0.0.5
   IbmZos
IbmWebsphere Application Server Version7.0.0.6
   IbmZos
IbmWebsphere Application Server Version7.0.0.7
   IbmZos
IbmWebsphere Application Server Version7.0.0.8
   IbmZos
IbmWebsphere Application Server Version7.0.0.9
   IbmZos
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.3% 0.503
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.