QID 378482
Date Published: 2023-07-18
QID 378482: IBM WebSphere Application Server Spoofing Vulnerability (6987779)
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to spoofing via the optional and separately installable Web Server Plug-ins for IBM WebSphere Application Server component. This has been addressed in the remediation section.
Affected Versions:
WebSphere Application Server Version V9.0.0.0 through 9.0.5.15
WebSphere Application Server Version V8.5.0.0 through 8.5.5.23
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.
This vulnerability allow a remote attacker to authenticated user to conduct spoofing attacks
Solution
Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix 6987779
Vendor References
- 6987779 -
www.ibm.com/support/pages/node/6987779
CVEs related to QID 378482
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6987779 |
|