QID 375670
Date Published: 2021-07-19
QID 375670: IBM WebSphere Application Server Multiple Vulnerabilities (6453091)
IBM WebSphere Application Server is affected by multiple vulnerabilities in Apache HttpComponents and HttpCommons libraries.
Affected Versions:
WebSphere Application Server V9.0.0.0 through 9.0.5.7
WebSphere Application Server V8.5.0.0 through 8.5.5.19
WebSphere Application Server V8.0.0.0 through 8.0.0.15
QID Detection Logic (Authenticated):
This QID checks for the vulnerable version of IBM WebSphere Application Server and checks if the patches are installed or not.
QID Detection Logic (Unauthenticated):
This QID matches vulnerable versions via the GIOP banner.
An attacker could exploit this vulnerability to accumulate multiple connections and exhaust all available resources.(CVE-2015-5262)
An attacker could exploit this vulnerability using man-in-the-middle techniques to spoof an SSL server.(CVE-2014-3577,CVE-2012-6153)
An attacker could exploit this vulnerability to send the Proxy-Authorization header to the host and disclose the user's password.(CVE-2011-1498)
- 6453091 -
www.ibm.com/support/pages/node/6453091
CVEs related to QID 375670
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| IBM WebSphere Application Server(6453091) |
|