CVE-2023-35890: IBM WebSphere Application Server information disclosure
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637.
Other sources
IBM WebSphere Application Server could provide weaker than expected security, caused by the improper encoding in a local configuration file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-35890?
CVE-2023-35890 is a vulnerability in IBM WebSphere Application Server 8.5 and 9.0 that could result in weaker than expected security due to improper encoding in a local configuration file.
What is the severity of CVE-2023-35890?
The severity of CVE-2023-35890 is medium with a CVSS score of 5.5.
Which software versions are affected by CVE-2023-35890?
IBM WebSphere Application Server versions 8.5.5.23, 9.0.5.15, and 9.0.5.16 as well as versions up to 8.5 and 9.0 are affected by CVE-2023-35890.
How can I fix CVE-2023-35890?
To fix CVE-2023-35890, update your IBM WebSphere Application Server to a version that is not affected by the vulnerability. Refer to IBM's official documentation for specific upgrade instructions.
Where can I find more information about CVE-2023-35890?
You can find more information about CVE-2023-35890 on the IBM Support website and the IBM X-Force Exchange website.