QID 376938

Date Published: 2022-08-30

QID 376938: IBM WebSphere Application Server Information Disclosure Vulnerability (6603421)

IBM WebSphere Application Server is vulnerable to an information disclosure vulnerability.

Affected Versions:
WebSphere Application Server V9.0.0.0 through 9.0.5.12
WebSphere Application Server V8.5.0.0 through 8.5.5.21
WebSphere Application Server V8.0.0.0 through 8.0.0.15
WebSphere Application Server V7.0.0.0 through 7.0.0.45

QID Detection Logic (Authenticated):
This QID checks for the vulnerable version of IBM WebSphere Application Server and checks if the patches are installed or not.

Successful exploitation could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released patches. Please visit IBM WebSphere Application Server(6603421) for more information.
    Vendor References

    CVEs related to QID 376938

    Software Advisories
    Advisory ID Software Component Link
    6603421 URL Logo www.ibm.com/support/pages/node/6603421