Impact
The vulnerability, identified as CWE-650, allows a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet. This information disclosure can expose directory structures, file names, and other metadata that might aid in subsequent attacks, compromising confidentiality.
Affected Systems
IBM WebSphere Application Server versions 8.5.0 through 8.5.5.30 and 9.0.0 through 9.0.5.28 are affected. The recommended fix is to apply Fix Pack 9.0.5.29 SB0030823 or a later pack for WebSphere 9, and to apply Pack 8.5.5.31 or a later pack for WebSphere 8.5.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of <1% signifies a low exploitation probability. Although it is not currently listed in the CISA KEV, the vulnerability can still be leveraged remotely if the FileTransfer servlet is exposed, allowing attackers to gather file system metadata that could aid in further attacks.
OpenCVE Enrichment