First published: Fri Aug 22 2014(Updated: )
IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server | =8.5.0.0 | |
IBM WebSphere Application Server | =8.5.0.1 | |
IBM WebSphere Application Server | =8.5.0.2 | |
IBM WebSphere Application Server | =8.5.5.0 | |
IBM WebSphere Application Server | =8.5.5.1 | |
IBM WebSphere Application Server | =8.5.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4767 is classified as a high severity vulnerability due to the potential for remote code execution.
To remediate CVE-2014-4767, upgrade IBM WebSphere Application Server Liberty Profile to version 8.5.5.3 or later.
CVE-2014-4767 affects IBM WebSphere Application Server Liberty Profile versions 8.5.0.0 through 8.5.5.2.
CVE-2014-4767 can be exploited by remote authenticated users who have knowledge of the affected system.
Attackers exploiting CVE-2014-4767 can execute arbitrary code on the server, potentially compromising the entire system.