CVE-2012-4850: Input Validation
Published Nov 14, 2012
·Updated
IBM WebSphere Application Server 8.5 Liberty Profile before 8.5.0.1, when JAX-RS is used, does not properly validate requests, which allows remote attackers to gain privileges via unspecified vectors.
Affected Software
1 affected component
IBM WebSphere Application Server Feature Pack for Web Services=8.5.0.0
Event History
Nov 14, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4850?
CVE-2012-4850 is considered a medium severity vulnerability that may allow remote attackers to gain privileges.
2
How do I fix CVE-2012-4850?
To fix CVE-2012-4850, upgrade to IBM WebSphere Application Server 8.5 Liberty Profile version 8.5.0.1 or later.
3
What versions of IBM WebSphere Application Server are affected by CVE-2012-4850?
CVE-2012-4850 affects IBM WebSphere Application Server 8.5 Liberty Profile version 8.5.0.0.
4
What type of attacks does CVE-2012-4850 allow?
CVE-2012-4850 allows remote attackers to potentially gain elevated privileges.
5
When was CVE-2012-4850 disclosed?
CVE-2012-4850 was disclosed as an issue in the IBM WebSphere Application Server prior to the release of version 8.5.0.1.