IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
The vulnerability results from unsafe processing of serialized Java objects (CWE-502 — deserialization of untrusted data). An attacker remotely sends a specially crafted sequence of serialized objects, which when processed by the server leads to arbitrary code execution. The attack does not require authentication or user interaction, however it requires a certain degree of complexity on the attacker's side (AC:H).
Successful exploitation of this vulnerability allows a remote attacker to execute arbitrary code on the server with the privileges of the IBM WebSphere process, which may result in complete system compromise, breach of confidentiality, integrity, and availability of data.
Apply patches available from the vendor according to the references — details available at: https://www.ibm.com/support/pages/node/7237967
IBM WebSphere Application Server 8.5 and 9.0 running on HP-UX, Linux, IBM z/OS, and IBM AIX systems
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HHP Ux
OSHpall versionsIBM Aix
OSIbmall versionsIBM I
OSIbmall versionsIBM Websphere Application Server
APPIbm8.5 – 8.5.5.28 (excl.)9.0 – 9.0.5.25 (excl.)IBM Z\/os
OSIbmall versionsLinux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versionsOracle Solaris
OSOracleall versions
Related vulnerabilities
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit