QID 378635

Date Published: 2023-07-18

QID 378635: IBM WebSphere Application Server Improper Encoding Vulnerability (7007857)

IBM WebSphere Application Server is vulnerable to improper encoding.

Affected Versions:
WebSphere Application Server Version 9.0.5.15 through 9.0.5.16
WebSphere Application Server Version 8.5.5.23

QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version and also checks for fix pack version.

This vulnerability allow a remote attacker to exploit this vulnerability to expose sensitive information due to improper encoding of local configuration file.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Upgrade to minimal fix pack levels7007671 or Apply Fix Pack 9.0.5.17 or later for 9.0 versions and 8.5.5.24 or later for 8.5 versions.

    CVEs related to QID 378635

    Software Advisories
    Advisory ID Software Component Link
    7007671 URL Logo www.ibm.com/support/pages/node/7007671