QID 378725
Date Published: 2023-08-21
QID 378725: IBM WebSphere Application Server Liberty Spoofing Attack Vulnerability (6569505)
There are multiple vulnerabilities in the swagger-ui library used by IBM WebSphere Application Server Liberty with mpOpenAPI-1.0, mpOpenAPI-1.1, mpOpenAPI-2.0, mpOpenAPI-3.0, openapi-3.0 or the openapi-3.1 feature enabled. These vulnerabilities could allow spoofing attacks or clickjacking vulnerabilities. This has been addressed.
Affected Versions:
WebSphere Application Server Liberty Version 21.0.0.12 - 22.0.0.1
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.
Vulnerable to identity spoofing by an authenticated user using a specially crafted request
Solution
Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix 6569505
Vendor References
- 6569505 -
www.ibm.com/support/pages/node/6569505
CVEs related to QID 378725
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6569505 |
|