Wednesday, March 6, 2019

IBM Security Bulletin: Multiple Security Vulnerabilities Affect IBM WebSphere Application Server in IBM Cloud

There are multiple security vulnerabilities that affect the IBM WebSphere Application Server in the IBM Cloud. There is a timing window where there could be a privilege escalation vulnerability in WebSphere Application Server. There is a potential remote code execution vulnerability in WebSphere Application Server. There is a potential cross-site request forgery in WebSphere Application Server Admin Console. There is a potential XXE injection vulnerability in the Knowledge Center used by WebSphere Application Server. There is a potential information disclosure in WebSphere Application Server. There is a potential for weaker than expected security in WebSphere Application Server with SP800-131 transition mode and SSL_TLSv2. There is a potential denial of service with the Google Guava library that is used in WebSphere Application Server.

CVE(s): CVE-2018-1901, CVE-2018-1904, CVE-2018-1905, CVE-2018-1926, CVE-2018-1957, CVE-2018-1996, CVE-2018-10237

Affected product(s) and affected version(s):

This vulnerability affects the following versions and releases of IBM WebSphere Application Server in IBM Cloud:

  • Liberty
  • Version 9.0
  • Version 8.5

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10793597
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152530
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152533
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152534
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152992
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/153629
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/154650
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/142508

The post IBM Security Bulletin: Multiple Security Vulnerabilities Affect IBM WebSphere Application Server in IBM Cloud appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2TwUMPZ

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.