QID 375699

Date Published: 2021-07-27

QID 375699: IBM WebSphere Application Server information disclosure (163177)

IBM WebSphere Application Server is vulnerable to a Privilege Escalation vulnerability.

Affected Versions:
WebSphere Application Server V9.0.0.0 through 9.0.5.1
WebSphere Application Server V8.5.0.0 through 8.5.5.16
WebSphere Application Server V8.0.0.0 through 8.0.0.15
WebSphere Application Server V7.0.0.0 through 7.0.0.45

Successful exploitation could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released patches. Please visit IBM WebSphere Application Server(2019-4441)for more information.
    Vendor References

    CVEs related to QID 375699

    Software Advisories
    Advisory ID Software Component Link
    BM WebSphere Application Server(2019-4441) URL Logo www.ibm.com/support/pages/security-bulletin-information-disclosure-vulnerability-websphere-application-server-cve-2019-4441