Lucene search

K
ibmIBM906523B00FBD734055A2D06A43B2EB6E9B4B3EB1C5F28E932797707DEEC6E700
HistoryJun 24, 2024 - 2:21 p.m.

Security Bulletin: Vulnerability has been identified in WebSphere Application Server shipped with WebSphere Service Registry and Repository (CVE-2024-37532)

2024-06-2414:21:45
www.ibm.com
4
websphere
application server
identity spoofing
vulnerability
security bulletin
ibm

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Summary

WebSphere Application Server is shipped as a component of WebSphere Service Registry and Repository. Information about an identity spoofing vulnerability affecting WebSphere Application Server has been published in a security bulletin.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
WebSphere Service Registry and Repository 8.5

Remediation/Fixes

For WebSphere Application Server shipped with WebSphere Service Registry and Repository refer to the following security bulletin for vulnerability details and information about fixes:

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmwebsphere_service_registry_and_repositoryMatch8.5

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for 906523B00FBD734055A2D06A43B2EB6E9B4B3EB1C5F28E932797707DEEC6E700