First published: Thu May 01 2014(Updated: )
IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote attackers to read arbitrary files via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.8 | |
=8.5.0.0 | ||
=8.5.0.1 | ||
=8.5.0.2 | ||
=8.5.5.0 | ||
=8.5.5.1 | ||
=7.0 | ||
=8.0.0.0 | ||
=8.0.0.1 | ||
=8.0.0.2 | ||
=8.0.0.3 | ||
=8.0.0.4 | ||
=8.0.0.5 | ||
=8.0.0.6 | ||
=8.0.0.7 | ||
=8.0.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0823 has a severity rating that may depend on the specific configuration and environment of the IBM WebSphere Application Server but is generally considered critical due to its ability to allow remote access to sensitive files.
To fix CVE-2014-0823, you should upgrade your IBM WebSphere Application Server to version 8.0.0.9 or 8.5.5.2 or later.
CVE-2014-0823 affects IBM WebSphere Application Server versions 7.0, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2.
Attackers exploiting CVE-2014-0823 can read arbitrary files from the IBM WebSphere Application Server through crafted URLs, potentially exposing sensitive data.
While upgrading is the primary solution, temporarily restricting access to the web server or implementing additional network security measures may help mitigate the risk of CVE-2014-0823.