QID 375653

Date Published: 2021-07-27

QID 375653: IBM WebSphere Application Server information disclosure (177841)

IBM WebSphere Application Server is vulnerable to a Privilege Escalation vulnerability.

Affected Versions:
WebSphere Application Server V9.0.0.0 through 9.0.5.3
WebSphere Application Server V8.5.0.0 through 8.5.5.17
WebSphere Application Server V8.0.0.0 through 8.0.0.15
WebSphere Application Server V7.0.0.0 through 7.0.0.45

Successful exploitation could allow a remote attacker to obtain sensitive information with a specially crafted sequence of serialized objects.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    The vendor has released patches. Please visitIBM WebSphere Application Server(2020-4329) for more information.
    Vendor References

    CVEs related to QID 375653

    Software Advisories
    Advisory ID Software Component Link
    IBM WebSphere Application Server(2020-4329) URL Logo www.ibm.com/support/pages/security-bulletin-information-disclosure-websphere-application-server-cve-2020-4329