QID 378724

Date Published: 2023-08-02

QID 378724: IBM WebSphere Application Server Liberty Information Disclosure Vulnerability (6585704)

IBM WebSphere Application Server Liberty is vulnerable to an information disclosure with the adminCenter-1.0 feature enabled. This has been addressed.

Affected Versions:
IBM WebSphere Application Server Liberty Version 17.0.0.3 to 22.0.0.5

QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version and also checks for fix pack version.

By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Upgrade to minimal fix pack levels6585704 or Apply Liberty Fix Pack 22.0.0.6 or later for 17.0.0.3 - 22.0.0.5
    Vendor References

    CVEs related to QID 378724

    Software Advisories
    Advisory ID Software Component Link
    6585704 URL Logo www.ibm.com/support/pages/node/6585704