QID 376565

Date Published: 2022-06-01

QID 376565: IBM WebSphere Application Server Remote Code Execution (RCE) Vulneraibilty (6558594)

IBM WebSphere Application Server is vulnerable to a Denial of Service.

Affected Versions:

Affected Versions:
WebSphere Application Server V9.0.0.0 through 9.0.5.11
WebSphere Application Server V8.5.0.0 through 8.5.5.21
WebSphere Application Server V8.0.0.0 through 8.0.0.15
WebSphere Application Server V7.0.0.0 through 7.0.0.45

QID Detection Logic (Authenticated):
This QID checks for the vulnerable version of IBM WebSphere Application Server and checks if the patches are installed or not.

There is a vulnerability in the Dojo library used by IBM WebSphere Application Server traditional in the Admin Console and used by the IBM WebSphere Application Server Liberty with the adminCenter-1.0 feature enabled that allows arbitrary code to be executed in the browser

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released patches. Please visit IBM WebSphere Application Server(6558594) for more information.

    CVEs related to QID 376565

    Software Advisories
    Advisory ID Software Component Link
    6558594 URL Logo www.ibm.com/support/pages/security-bulletin-ibm-websphere-application-server-vulnerable-remote-code-execution-due-dojo-cve-2021-23450