CVE-2016-0378: IBM WebSphere Application Server

Low severity, CVSS 3.7. EPSS: 1.7% chance of exploitation in the next 30 days.

IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3, when the installation lacks a default error page, allows remote attackers to obtain sensitive information by triggering an exception.

Affected products

  • IBM WebSphere Application Server: up to and including 16.0.0.2

Published 2016-11-24. Last modified 2026-06-17.