Security Bulletin
Summary
An Information disclosure vulnerability was addressed by IBM InfoSphere Information Server.
Vulnerability Details
DESCRIPTION: IBM InfoSphere Information Server displays sensitive information in version numbers of installed software that could aid a remote attacker in further attacks against the system.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/168641 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Affected Products and Versions
IBM InfoSphere Information Server: version 11.7
IBM InfoSphere Information Server on Cloud: version 11.7
Remediation/Fixes
Update your configuration by issuing the following command on the Microservices tier master node:
1. Go to Servers > Server Types > WebSphere application servers > server_name > Web Container Settings > Web container
4. On the Settings page
b. set the value for the property to true
c. Click Apply or OK
5. Click Save on the console task bar to save your configuration changes
6. Restart the server
For additional information, see https://www.ibm.com/support/pages/node/6587569.
Get Notified about Future Security Bulletins
References
Change History
11 October 2019: Original version published
24 August 2022: com.ibm.ws.webcontainer.disablexPoweredBy should be set to true
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Internal Use Only
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
25 August 2022
UID
ibm11085559