QID 379592
QID 379592: IBM WebSphere Application Server and IBM WebSphere Application Server Liberty Denial of Service (DoS) Vulnerability (7145942)
There is a vulnerability in the jose4j library used by IBM WebSphere Application Server traditional and used by the IBM WebSphere Application Server Liberty.
jose4j is vulnerable to a denial of service, caused by improper input validation. By sending a specially crafted p2c value, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Affected Versions:
BM WebSphere Application Server Liberty v21.0.0.3 - v24.0.0.3
IBM WebSphere Application Server v9.0
IBM WebSphere Application Server v8.5
QID Detection Logic:(Authenticated)
It reads the fix xml file and WebSphereApplicationServer.properties to detect the vulnerable version. and it also checks for fixpack version.
Successful exploit by a remote attacker could exploit this vulnerability to cause a denial of service condition.
- 7145942 -
www.ibm.com/support/pages/node/7145942
CVEs related to QID 379592
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| v |
|