QID 378541

Date Published: 2023-06-26

QID 378541: IBM WebSphere Application Server Multiple Vulnerabilities (6980375)

An unspecified vulnerability in Java SE related to the Serialization component could allow a remote attacker to cause a denial of service resulting in a low integrity impact using unknown attack vectors.

An unspecified vulnerability in Java SE related to the JAXP component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.

Affected Versions:
WebSphere Application Server 8.5.0.0 through 8.5.5.23

QID Detection Logic (Authenticated):
This QID checks for the vulnerable version of IBM WebSphere Application Server and checks if the patches are installed or not.

Successful exploitation could allow denial of service resulting in a low integrity impact using unknown attack vectors

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released patches. Please visit IBM WebSphere Application Server(6980375) for more information.
    Vendor References

    CVEs related to QID 378541

    Software Advisories
    Advisory ID Software Component Link
    6980375 URL Logo www.ibm.com/support/pages/node/6980375