IBM Security Bulletin: Content Collector for Email affected by information disclosure vulnerability in Websphere Application Server
Apr 13, 2018 9:00 am EDT
Categorized: Medium Severity
Share this post:
Content Collector for Email has addressed the following vulnerability. IBM Websphere Application Server could allow a local attacker to obtain sensitive information, caused by improper handling of application requests, which could allow unauthorized access to read a file.
CVE(s): CVE-2017-1681
Affected product(s) and affected version(s):
Content Collector for Email 3.0 – 4.0.1
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=swg22015032
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/134003
from IBM Product Security Incident Response Team https://ift.tt/2qsp6vy