Lucene search

K
ibmIBM90348D6772DE9E48DF6101199D8CF4699FCF9FC63DF44E1957B78FF9DAA92724
HistoryApr 11, 2023 - 4:14 p.m.

Security Bulletin: IBM WebSphere Application Server Liberty, which is bundled with IBM Cloud Pak for Applications, is vulnerable to a privilege escalation due to RESTEasy (CVE-2023-0482)

2023-04-1116:14:56
www.ibm.com
10
ibm
cloud pak
applications
websphere
vulnerable
privilege escalation
resteasy
cve-2023-0482
security bulletin.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

5.1%

Summary

IBM WebSphere Application Server Liberty, which is bundled with IBM Cloud Pak for Applications, is vulnerable to a privilege escalation due to RESTEasy (CVE-2023-0482)

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) and Version(s) Affecting Product(s) and Version(s)

IBM Cloud Pak for Applications

  • 5.1
    |

IBM WebSphere Application Server Liberty

  • 21.0.0.12 - 23.0.0.3

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the APAR PH52739 as described in Security Bulletin: IBM WebSphere Application Server Liberty is vulnerable to a privilege escalation due to RESTEasy (CVE-2023-0482).

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_pak_for_applicationsMatch5.1
VendorProductVersionCPE
ibmcloud_pak_for_applications5.1cpe:2.3:a:ibm:cloud_pak_for_applications:5.1:*:*:*:*:*:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

5.1%

Related for 90348D6772DE9E48DF6101199D8CF4699FCF9FC63DF44E1957B78FF9DAA92724