Impact
A remote attacker can retrieve sensitive file system information by abusing the FileTransfer servlet in IBM WebSphere Application Server. The flaw allows disclosure of data that should remain confidential, representing an information disclosure vulnerability associated with improper authorization (CWE‑863). This does not grant code execution but can leak data useful for further attacks.
Affected Systems
All IBM WebSphere Application Server installations running 8.5.0.0 through 8.5.5.30 and 9.0.0.0 through 9.0.5.28 are affected. The specific versions lacking the fix package are those with a build number less than 8.5.5.31 for v8 and less than 9.0.5.29 for v9.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as medium severity and indicates limited impact on confidentiality alone. EPSS data is not provided, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely over the network by sending requests to the vulnerable FileTransfer servlet, without requiring local privileges.
OpenCVE Enrichment