QID 378002
Date Published: 2023-02-23
QID 378002: IBM WebSphere Application Server Remote Code Execution (RCE) Vulnerability (6891111)
BM WebSphere Application Server Liberty is vulnerable to Cross-Site Scripting.
Affected Versions:
WebSphere Application Server Version 9.0.0.0 through 9.0.5.7
WebSphere Application Server Version 8.5.0.0 through 8.5.5.19
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version and also checks for fix pack version.
This vulnerability allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
Solution
Upgrade to minimal fix pack levels6891111 or Apply Fix Pack 9.0.58 or later for 9.0 versions and 8.5.5.19 or later for 8.5 versions.
Vendor References
- 6891111 -
www.ibm.com/support/pages/node/6891111
CVEs related to QID 378002
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6891111 |
|