CVE-2019-4505: Medium severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL. This can lead the attacker to view any file in a certain directory. IBM X-Force ID: 164364.
Other sources
IBM WebSphere Application Server Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL. This can lead the attacker to view any file in a certain directory.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-4505.
What is the severity of CVE-2019-4505?
The severity of CVE-2019-4505 is medium with a CVSS score of 5.3.
What is the affected software?
The affected software is IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 Network Deployment, as well as IBM WebSphere Virtual Enterprise versions 7.0 and 8.0.
How can a remote attacker exploit CVE-2019-4505?
A remote attacker can exploit CVE-2019-4505 by sending a specially-crafted URL, which allows them to obtain sensitive information and view files in a certain directory.
Where can I find more information about CVE-2019-4505?
You can find more information about CVE-2019-4505 at the following IBM X-Force ID: 164364 and IBM Support pages [^1^] [^2^].