Total vulnerabilities in the database
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-010 records DEBUG messages containing user credentials in the log4j.xml file, which might allow local users to obtain sensitive information by reading this file.
Software | From | Fixed in |
---|---|---|
ibm / filenet_p8_application_engine | 3.5.1-009 | 3.5.1-009.x |
ibm / filenet_p8_application_engine | 3.5.1-005 | 3.5.1-005.x |
ibm / filenet_p8_application_engine | 3.5.1-006 | 3.5.1-006.x |
ibm / filenet_p8_application_engine | 3.5.1-004 | 3.5.1-004.x |
ibm / filenet_p8_application_engine | 3.5.1 | 3.5.1.x |
ibm / filenet_p8_application_engine | 3.5.1-007 | 3.5.1-007.x |
ibm / filenet_p8_application_engine | 3.5.1-001 | 3.5.1-001.x |
ibm / filenet_p8_application_engine | 3.5.1-002 | 3.5.1-002.x |
ibm / filenet_p8_application_engine | 3.5.1-008 | 3.5.1-008.x |
ibm / filenet_p8_application_engine | 3.5.1-003 | 3.5.1-003.x |