QID 378357

Date Published: 2023-07-19

QID 378357: IBM WebSphere Application Server Liberty Denial of Service (DoS) Vulnerability (6824871)

IBM WebSphere Application Server Liberty is vulnerable to Denial of Service Vulnerability.

Affected Versions:
WebSphere Application Server Liberty Version 17.0.0.3 through 22.0.0.10

QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version and also checks for fix pack version.

Sparkle Motion Nokogiri is vulnerable to a denial of service, caused by a java.lang.OutOfMemoryError exception when parsing ill-formed HTML markup in the fork of org.cyberneko.html. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Upgrade to minimal fix pack levels6824871 or Apply Liberty Fix Pack 22.0.0.11 or later for 17.0.0.3 - 22.0.0.10.
    Vendor References

    CVEs related to QID 378357

    Software Advisories
    Advisory ID Software Component Link
    6824871 URL Logo www.ibm.com/support/pages/node/6824871