QID 378459
Date Published: 2023-06-28
QID 378459: IBM WebSphere Application Server Liberty Denial of Service (DoS) Vulnerability (6982047)
IBM WebSphere Application Server Liberty is vulnerable to an Denial Of Service.
Affected Versions:
WebSphere Application Server Liberty Version 17.0.0.3 - 23.0.0.3
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.
There is a vulnerability in the Apache Commons FileUpload library used by IBM WebSphere Application Server and used by IBM WebSphere Application Server Liberty with the servlet-3.0, servlet-3.1, servlet-4.0, servlet-5.0 or servlet-6.0 feature enabled.
Solution
Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix 6982047
Vendor References
- 6982047 -
www.ibm.com/support/pages/node/6982047
CVEs related to QID 378459
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6982047 |
|