QID 375474
Date Published: 2021-04-21
QID 375474: IBM WebSphere Application Server Information Disclosure Vulnerability(6339807)
IBM WebSphere Application Server is vulnerable to an information disclosure vulnerability.
Affected Versions:
WebSphere Application Server V9.0.0.0 through 9.0.5.5
WebSphere Application Server V8.5.0.0 through 8.5.5.18
WebSphere Application Server V8.0.0.0 through 8.0.0.15
WebSphere Application Server V7.0.0.0 through 7.0.0.45
QID Detection Logic (Authenticated):
This QID checks for the vulnerable version of IBM WebSphere Application Server and checks if the patches are installed or not.
QID Detection Logic (Unauthenticated):
This QID matches vulnerable versions via the GIOP banner.
Successful exploitation could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects.
Solution
The vendor has released patches. Please visit IBM WebSphere Application Server(6339807) for more information.
Vendor References
- IBM WebSphere Application Server(6339807) -
www.ibm.com/support/pages/node/6339807
CVEs related to QID 375474
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| IBM WebSphere Application Server(6339807) |
|