QID 375468

Date Published: 2021-04-20

QID 375468: IBM WebSphere Application Server Multiple Vulnerabilities(6415639)

IBM WebSphere Application Server multiple vulnerabilities

CVEID: CVE-2020-27221
DESCRIPTION: Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVEID: CVE-2020-2773
DESCRIPTION: An unspecified vulnerability in Java SE related to the Java SE Security component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVEID: CVE-2020-14782
DESCRIPTION: An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
CVEID: CVE-2020-14781
DESCRIPTION: An unspecified vulnerability in Java SE related to the JNDI component could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors

Affected Versions:
Affected Product(s) Version(s) WebSphere Application Server 9.0.0.0 WebSphere Application Server V8.5.5.9 through 8.5.5.19

QID Detection Logic (Authenticated):
This QID checks for the vulnerable version of IBM WebSphere Application Server and checks if the patches are installed or not.

QID Detection Logic (Unauthenticated):
This QID matches vulnerable versions Java

An attacker could send a specially-crafted URL request to view arbitrary files on the system but not content.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released patches. Please visit IBM WebSphere Application Server(6415639) for more information.
    Vendor References

    CVEs related to QID 375468

    Software Advisories
    Advisory ID Software Component Link
    IBM WebSphere Application Server(6415639) Windows URL Logo www.ibm.com/support/pages/node/6415639
    IBM WebSphere Application Server(6415639) Windows URL Logo www.ibm.com/support/pages/node/6415639