CVE-2014-3083

IBM WebSphere Application Server 7.0.x-7.0.0.35 8.0.x-8.0.0.10 8.5.x-8.5.5.3 - Information Disclosure

Title source: llm
STIX 2.1

Description

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource access, which allows remote attackers to obtain sensitive information via unspecified vectors.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69298
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/93954
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI17768
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21681249

Scores

EPSS 0.0212
EPSS Percentile 79.9%

Details

CWE
CWE-264
Status published
Products (45)
ibm/websphere_application_server 8.5.0.0
ibm/websphere_application_server 8.5.0.1
ibm/websphere_application_server 8.5.0.2
ibm/websphere_application_server 8.5.5.0
ibm/websphere_application_server 8.5.5.1
ibm/websphere_application_server 8.5.5.2
ibm/websphere_application_server 8.0.0.0
ibm/websphere_application_server 8.0.0.1
ibm/websphere_application_server 8.0.0.2
ibm/websphere_application_server 8.0.0.3
... and 35 more
Published Aug 22, 2014
Tracked Since Feb 18, 2026