QID 378460
Date Published: 2023-05-24
QID 378460: IBM WebSphere Application Server Denial Of Service (DOS) Vulnerability (6982047)
IBM WebSphere Application Server Liberty is vulnerable to an Denial Of Service.
Affected Versions:
WebSphere Application Server Version V9.0.0.0 through 9.0.5.15
WebSphere Application Server Version V8.5.0.0 through 8.5.5.23
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.
There is a vulnerability in the Apache Commons FileUpload library used by IBM WebSphere Application Server and used by IBM WebSphere Application Server Liberty with the servlet-3.0, servlet-3.1, servlet-4.0, servlet-5.0 or servlet-6.0 feature enabled.
Solution
Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix 6982047
Vendor References
- 6982047 -
www.ibm.com/support/pages/node/6982047
CVEs related to QID 378460
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6982047 |
|