QID 378241

Date Published: 2023-07-27

QID 378241: IBM WebSphere Application Server Liberty Information Disclosure Vulnerability (6953779)

IBM WebSphere Application Server is vulnerable to cross-site scripting.

Affected Versions:
IBM WebSphere Application Server Liberty Version 21.0.0.12 to 23.0.0.1

QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version and also checks for fix pack version.

By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Upgrade to minimal fix pack levels6953779 or Apply Liberty Fix Pack 23.0.0.2 or later for 21.0.0.12 - 23.0.0.1
    Vendor References

    CVEs related to QID 378241

    Software Advisories
    Advisory ID Software Component Link
    6953779 URL Logo www.ibm.com/support/pages/node/6953779