QID 378974

Date Published: 2024-01-04

QID 378974: IBM WebSphere Application Server Liberty Privilege Gain Vulnerability (7058356)

IBM WebSphere Application Server Liberty could provide weaker than expected security due to improper resource expiration handling

Affected Versions:
WebSphere Application Server Liberty Version 23.0.0.9 - 23.0.0.10
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.

Successful exploit might lead to privilege gain

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution
    For more information kindly refer 7058356
    Vendor References

    CVEs related to QID 378974

    Software Advisories
    Advisory ID Software Component Link
    7058356 URL Logo www.ibm.com/support/pages/node/7058356