QID 378720
Date Published: 2023-08-02
QID 378720: IBM WebSphere Application Server Liberty Identity Spoofing Vulnerability (6586734)
IBM WebSphere Application Server Liberty is vulnerable to identity spoofing with the appSecurity-1.0, appSecurity-2.0, appSecurity-3.0 or appSecurity-4.0 feature enabled. This has been addressed.
Affected Versions:
WebSphere Application Server Liberty Version 17.0.0.3 - 22.0.0.5
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.
Vulnerable to identity spoofing by an authenticated user using a specially crafted request
Solution
Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix 6586734
Vendor References
- 6586734 -
www.ibm.com/support/pages/node/6586734
CVEs related to QID 378720
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6586734 |
|