The host is running IBM WebSphere Application Server and is prone to information disclosure vulnerability.
Successful exploitation will let remote unauthorized attackers to access or view files or obtain sensitive information. Impact Level: Application
Apply the latest Fix Pack (126.96.36.199 or later) or APAR PM45992 http://www-01.ibm.com/support/docview.wss?uid=swg21474220
The flaw is caused by improper handling of requests in 'JSF' applications. A remote attacker could gain unauthorized access to view files on the host.
IBM WebSphere Application Server versions 8.x before 188.8.131.52
- Ecava IntegraXor Account Information Disclosure Vulnerability
- IBM WebSphere Application Server JNDI information disclosure Vulnerability
- Cherokee URI Directory Traversal Vulnerability and Information Disclosure Vulnerability
- Apache Tomcat Parameter Handling Denial of Service Vulnerability (Win)
- Cherokee Terminal Escape Sequence in Logs Command Injection Vulnerability