CVE-2018-16386: Swift Alliance Web Platform

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATH_INFO to swp/login/EJBRemoteService/, related to com.swift.ejbgwt.j2ee.client.EjBlnvocationException error log information containing null@java:comp/env/ error messages.

Affected products

  • Swift Alliance Web Platform: version 7.1.23 only

Published 2019-07-05. Last modified 2026-06-17.