QID 378733
Date Published: 2023-08-09
QID 378733: IBM WebSphere Application Server Liberty Denial of Service (DoS) Vulnerability (6841889)
IBM WebSphere Application Server Liberty is vulnerable to an Denial Of Service.
Affected Versions:
WebSphere Application Server Liberty Version 21.0.0.2 - 22.0.0.13
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.
There is a vulnerability in the Google protobuf-java library used by IBM WebSphere Application Server Liberty with the grpc-1.0 or grpcClient-1.0 feature enabled.
Solution
Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix 6841847
Vendor References
- 6841889 -
www.ibm.com/support/pages/node/6841889
CVEs related to QID 378733
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6841847 |
|