CVE-2014-8890: Medium severity ibm websphere application server feature pack for web services vulnerability
IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8890?
CVE-2014-8890 has been rated as a medium severity vulnerability, allowing remote privilege escalation.
How do I fix CVE-2014-8890?
You can fix CVE-2014-8890 by upgrading to IBM WebSphere Application Server Liberty Profile version 8.5.5.4 or later.
Who is affected by CVE-2014-8890?
CVE-2014-8890 affects IBM WebSphere Application Server Liberty Profile versions 8.5.0.0 through 8.5.5.3.
What kind of attack does CVE-2014-8890 enable?
CVE-2014-8890 enables remote attackers to gain elevated privileges on the affected system.
What components are involved in the exploitation of CVE-2014-8890?
The exploitation of CVE-2014-8890 involves a servlet's deployment descriptor security constraints and associated ServletSecurity annotations.