Lucene search

K
ibmIBMC806596FD531EE48C936FB8CCDFD1B4F2F6C8E681CD6E50EDD86C7737CB9ED30
HistoryApr 04, 2023 - 6:52 a.m.

Security Bulletin: A security vulnerability has been identified in WebSphere® Application Server shipped with IBM® Intelligent Operations Center (CVE-2023-26283)

2023-04-0406:52:33
www.ibm.com
6
websphere application server
ibm intelligent operations center
security bulletin
vulnerability
cross-site scripting
cve-2023-26283

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

18.0%

Summary

WebSphere® Application Server is shipped with IBM® Intelligent Operations Center. Information about a security vulnerability affecting WebSphere® Application Server has been published in a security bulletin.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
IBM Intelligent Operations Center 1.5.0, 1.6.0, 1.6.0.1, 1.6.0.2, 1.6.0.3
IBM Intelligent Operations Center for Emergency Management (Linux) 1.6.0

Remediation/Fixes

Download the correct version of the fix from the following link: Security Bulletin: IBM WebSphere Application Server is vulnerable to cross-site scripting in the Admin Console (CVE-2023-26283). Installation instructions for the fix are included in the readme document that is in the fix package.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmintelligent_operations_centerMatch1.5.0
OR
ibmintelligent_operations_centerMatch1.6.0
OR
ibmintelligent_operations_centerMatch1.6.0.1
OR
ibmintelligent_operations_centerMatch1.6.0.2
OR
ibmintelligent_operations_centerMatch1.6.0.3
OR
ibmintelligent_operations_centerMatch5.2.1
VendorProductVersionCPE
ibmintelligent_operations_center1.5.0cpe:2.3:a:ibm:intelligent_operations_center:1.5.0:*:*:*:*:*:*:*
ibmintelligent_operations_center1.6.0cpe:2.3:a:ibm:intelligent_operations_center:1.6.0:*:*:*:*:*:*:*
ibmintelligent_operations_center1.6.0.1cpe:2.3:a:ibm:intelligent_operations_center:1.6.0.1:*:*:*:*:*:*:*
ibmintelligent_operations_center1.6.0.2cpe:2.3:a:ibm:intelligent_operations_center:1.6.0.2:*:*:*:*:*:*:*
ibmintelligent_operations_center1.6.0.3cpe:2.3:a:ibm:intelligent_operations_center:1.6.0.3:*:*:*:*:*:*:*
ibmintelligent_operations_center5.2.1cpe:2.3:a:ibm:intelligent_operations_center:5.2.1:*:*:*:*:*:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

18.0%

Related for C806596FD531EE48C936FB8CCDFD1B4F2F6C8E681CD6E50EDD86C7737CB9ED30