QID 378346
Date Published: 2023-05-24
QID 378346: IBM WebSphere Application Server Liberty Server-Side Request Forgery (SSRF) Vulnerability (6953767)
IBM WebSphere Application Server is vulnerable to Server-Side Request Forgery(SSRF).
Affected Versions:
IBM WebSphere Application Server Liberty Version 17.0.0.3 to 23.0.0.1
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version and also checks for fix pack version.
Apache CXF is vulnerable to server-side request forgery, caused by a flaw in parsing the href attribute of XOP:Include in MTOM requests. By using a specially-crafted request, an attacker could exploit this vulnerability to conduct SSRF attack.
Solution
Upgrade to minimal fix pack levels6953767 or Apply Liberty Fix Pack 23.0.0.2 or later for 17.0.0.3 - 23.0.0.1
Vendor References
- 6953767 -
www.ibm.com/support/pages/node/6953767
CVEs related to QID 378346
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6953767 |
|