QID 378349
Date Published: 2023-06-28
QID 378349: IBM WebSphere Application Server Liberty Denial of Service (DoS) Vulnerability (6832094)
IBM WebSphere Application Server is vulnerable to Denial of Service.
Affected Versions:
IBM WebSphere Application Server Liberty Version 17.0.0.3 to 22.0.0.11
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version and also checks for fix pack version.
GraphQL Java is vulnerable to a denial of service, caused by an uncontrolled resource consumption flaw. By sending a specially-crafted request using Directive overloading, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Solution
Upgrade to minimal fix pack levels6832094 or Apply Liberty Fix Pack 22.0.0.12 or later for 17.0.0.3 -22.0.0.11
Vendor References
- 6832094 -
www.ibm.com/support/pages/node/6832094
CVEs related to QID 378349
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6832094 |
|