First published: Wed Jun 28 2023(Updated: )
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Application Server | =8.5.5.23 | |
Ibm Websphere Application Server | =9.0.5.15 | |
Ibm Websphere Application Server | =9.0.5.16 | |
Ibm Websphere Application Server | <=9.0 | |
Ibm Websphere Application Server | <=8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35890 is a vulnerability in IBM WebSphere Application Server 8.5 and 9.0 that could result in weaker than expected security due to improper encoding in a local configuration file.
The severity of CVE-2023-35890 is medium with a CVSS score of 5.5.
IBM WebSphere Application Server versions 8.5.5.23, 9.0.5.15, and 9.0.5.16 as well as versions up to 8.5 and 9.0 are affected by CVE-2023-35890.
To fix CVE-2023-35890, update your IBM WebSphere Application Server to a version that is not affected by the vulnerability. Refer to IBM's official documentation for specific upgrade instructions.
You can find more information about CVE-2023-35890 on the IBM Support website and the IBM X-Force Exchange website.