Security Bulletin: Vulnerabilities in IBM WebSphere Application Server Liberty affect BM Spectrum Control
Discription

Summary IBM WebSphere Application Server Liberty is vulnerable to allow a remote authenticated attacker, denial of service, server-side request forgery (SSRF), cross-site scripting, improper resource expiration handling, weaker than expected security for outbound TLS connections. These vulnerabilities affect IBM Spectrum Control. CVE-2023-44483, CVE-2023-51775, CVE-2024-22353, CVE-2024-22329, CVE-2023-44487, CVE-2024-27270, CVE-2024-25026, CVE-2023-46158, CVE-2023-50312. Vulnerability Details ** CVEID: CVE-2023-44483 DESCRIPTION: **Apache Santuario could allow a remote authenticated attacker to obtain sensitive information, caused by the storage of a private key in the log files when using the JSR 105 API. By gaining access to the log files, an attacker could exploit this vulnerability to obtain the private key information, and use this information to launch further attacks against the affected system. CVSS Base score: 6.5 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/269153 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) ** CVEID: CVE-2023-51775 DESCRIPTION: **jose4j is vulnerable to a denial of service, caused by improper input validation. By sending a specially crafted p2c value, a remote attacker could exploit this vulnerability to cause a denial of service condition. CVSS Base score: 7.5 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/275907 for the current score….Read More

Back to Main

Subscribe for the latest news: