QID 378729
Date Published: 2023-08-14
QID 378729: IBM WebSphere Application Server Liberty Denial of Service (DoS) Vulnerability (6999681)
IBM WebSphere Application Server Liberty is vulnerable to an Denial Of Service.
Affected Versions:
WebSphere Application Server Liberty Version 17.0.0.3 - 23.0.0.5
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.
There is a vulnerability in the GraphQL Java library used by IBM WebSphere Application Server Liberty when the feature mpGraphQL-1.0 or mpGraphQL-2.0 is enabled.
Solution
Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix 6999681
Vendor References
- 6999681 -
www.ibm.com/support/pages/node/6999681
CVEs related to QID 378729
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6999681 |
|