QID 375818

Date Published: 2021-12-27

QID 375818: IBM WebSphere Application Server Java Software Development Kit (SDK) Vulnerability (6481135)

There are multiple vulnerabilities in the IBM SDK, Java Technology Edition that is shipped with IBM WebSphere Application Server.

CVE-2021-2369: An unspecified vulnerability in Java SE related to the Library component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.

Affected Versions:
WebSphere Application Server V9.0.0.0
WebSphere Application Server V8.5.0.0 through 8.5.5.20

QID Detection Logic (Authenticated):
This QID checks for the vulnerable version of IBM WebSphere Application Server 8.5.0.0 through 8.5.5.20 and checks if the patches are installed or not.

QID Detection Logic (Authenticated):
This QID matches vulnerable versions Java and IBM WebSphere Application server 9.0.0.0

Successful exploit could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    The vendor has released patches. Please visit IBM WebSphere Application Server(6481135) for more information.
    Vendor References

    CVEs related to QID 375818

    Software Advisories
    Advisory ID Software Component Link
    6481135 URL Logo www.ibm.com/support/pages/node/6481135