QID 379431

QID 379431: IBM WebSphere Application ServerJava SDK Vulnerability (7058356)

IBM WebSphere Application Server Liberty could provide weaker than expected security due to improper resource expiration handling

Affected Versions:
WebSphere Application Server Liberty Version 8.5,9.0
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.

Remote code execution (RCE) refers to a class of cyberattacks in which attackers remotely execute commands to place malware or other malicious code on your computer or network.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution
    For more information kindly refer 7117872
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    7117872 URL Logo www.ibm.com/support/pages/node/7117872