There is an information disclosure vulnerability in IBM WebSphere Application Server Liberty. IBM WebSphere Application Server Liberty is used by IBM MessageSight. IBM MessageSight has addressed the applicable CVE.
CVEID: CVE-2011-4343**
DESCRIPTION:** Apache MyFaces could allow a remote attacker to obtain sensitive information. An attacker could exploit this vulnerability using specially crafted parameters to inject EL expressions into input fields mapped as view parameters and obtain sensitive information.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/132287 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Affected IBM MessageSight
| Affected Versions
—|—
IBM MessageSight| v1.1 - 1.1.0.1
IBM MessageSight| v1.2 – 1.2.0.3
IBM MessageSight| v2.0 – 2.0.0.2
Product
| VRMF| APAR| Remediation/First Fix
—|—|—|—
IBM MessageSight| 1.1| IT23078| 1.1.0.1-IBM-IMA-IFIT23384
IBM MessageSight| 1.2| IT23078| 1.2.0.3-IBM-IMA-IFIT23384
IBM MessageSight| 2.0| IT23078| 2.0.0.2-IBM-IMA-IFIT23078
CPE | Name | Operator | Version |
---|---|---|---|
ibm messagesight | eq | 1.1 | |
ibm messagesight | eq | 1.2 | |
ibm messagesight | eq | 2.0 |