There are multiple security vulnerabilities that affect the IBM WebSphere Application Server in the IBM Cloud. There is a timing window where there could be a privilege escalation vulnerability in WebSphere Application Server. There is a potential remote code execution vulnerability in WebSphere Application Server. There is a potential cross-site request forgery in WebSphere Application Server Admin Console. There is a potential XXE injection vulnerability in the Knowledge Center used by WebSphere Application Server. There is a potential information disclosure in WebSphere Application Server. There is a potential for weaker than expected security in WebSphere Application Server with SP800-131 transition mode and SSL_TLSv2. There is a potential denial of service with the Google Guava library that is used in WebSphere Application Server.
CVE(s): CVE-2018-1901, CVE-2018-1904, CVE-2018-1905, CVE-2018-1926, CVE-2018-1957, CVE-2018-1996, CVE-2018-10237
Affected product(s) and affected version(s):
This vulnerability affects the following versions and releases of IBM WebSphere Application Server in IBM Cloud:
- Liberty
- Version 9.0
- Version 8.5
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10793597
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152530
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152533
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152534
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152992
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/153629
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/154650
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/142508
The post IBM Security Bulletin: Multiple Security Vulnerabilities Affect IBM WebSphere Application Server in IBM Cloud appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/2TwUMPZ
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.