IBM WebSphere Application Server 9.0 i WebSphere Application Server Liberty w wersjach od 17.0.0.3 do 25.0.0.7 mogą pozwolić zdalnemu atakującemu obejść ograniczenia bezpieczeństwa z powodu nierespektowania konfiguracji bezpieczeństwa.
▸ Pokaż oryginał (EN)
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NIBM Websphere Application Server
APPIbm9.0.0.017.0.0.3 – 25.0.0.7
Powiązane podatności
RCE w produktach IBM via deserializacja Java (Apache Commons Collections)
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty ...
XSS w konsoli administracyjnej IBM Tivoli System Automation Application Manager 4.1
SSRF w IBM WebSphere Application Server przy włączonej funkcji SIP container
IBM WebSphere Application Server — privilege escalation w konsoli administracyjnej