QID 378604
Date Published: 2023-07-04
QID 378604: IBM WebSphere Application Server Liberty Identity Spoofing Vulnerability (6602015)
IBM WebSphere Application Server Liberty is vulnerable to identity spoofing with the appSecurity-1.0, appSecurity-2.0, appSecurity-3.0 or appSecurity-4.0 feature enabled. This has been addressed.
Affected Versions:
WebSphere Application Server Liberty Version 17.0.0.3 - 22.0.0.7
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.
Vulnerable to identity spoofing by an authenticated user using a specially crafted request
Solution
Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix 6602015
Vendor References
- 6602015 -
www.ibm.com/support/pages/node/6602015
CVEs related to QID 378604
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6602015 |
|