CVE-2014-4767: Code Injection
IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4767?
CVE-2014-4767 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2014-4767?
To remediate CVE-2014-4767, upgrade IBM WebSphere Application Server Liberty Profile to version 8.5.5.3 or later.
What software is affected by CVE-2014-4767?
CVE-2014-4767 affects IBM WebSphere Application Server Liberty Profile versions 8.5.0.0 through 8.5.5.2.
Who can exploit CVE-2014-4767?
CVE-2014-4767 can be exploited by remote authenticated users who have knowledge of the affected system.
What can attackers do with CVE-2014-4767?
Attackers exploiting CVE-2014-4767 can execute arbitrary code on the server, potentially compromising the entire system.