Lucene search

K
ibmIBM280F22C59D289D09BF95C27BCBD4E75FDD23E4CB97EDC3D26F891DF09095112C
HistoryOct 06, 2020 - 12:53 a.m.

Security Bulletin: Multiple Security Vulnerabilities fixed in IBM WebSphere Liberty as shipped in IBM Security Access Manager

2020-10-0600:53:38
www.ibm.com
19
ibm
security access manager
websphere liberty
vulnerabilities
cve-2019-4304
cve-2019-4305
cve-2019-4720
denial of service
isam 9.0
isam 8.0
update

EPSS

0.001

Percentile

47.8%

Summary

IBM Security Access Manager has shipped fixes that were fixed in IBM Security WebSphere Liberty.

Vulnerability Details

CVEID:CVE-2019-4304
**DESCRIPTION:**IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/160950 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

CVEID:CVE-2019-4305
**DESCRIPTION:**IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the improper setting of a cookie. IBM X-Force ID: 160951.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/160951 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID:CVE-2019-4720
**DESCRIPTION:**IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available memory. IBM X-Force ID: 172125.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/172125 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
ISAM 9.0
ISAM 8.0

Remediation/Fixes

Product Name VRMF APAR Remediation/First Fix
IBM Security Access Manager 8.0.1 IJ24609 8.0.1-ISS-WGA-FP0009
IBM Security Access Manager 9.0.7.1 IJ24609 9.0.7.1-ISS-ISAM-IF0005

Workarounds and Mitigations

None

EPSS

0.001

Percentile

47.8%

Related for 280F22C59D289D09BF95C27BCBD4E75FDD23E4CB97EDC3D26F891DF09095112C