CVE-2023-50313: IBM WebSphere Application Server information disclosure
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274812.
Other sources
IBM WebSphere Application Server could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50313?
CVE-2023-50313 has a medium severity rating due to potential weaknesses in outbound TLS connections.
How do I fix CVE-2023-50313?
To fix CVE-2023-50313, ensure that your IBM WebSphere Application Server configurations are set correctly to honor the desired security settings.
Which versions of IBM WebSphere Application Server are affected by CVE-2023-50313?
CVE-2023-50313 affects IBM WebSphere Application Server versions 8.5 and 9.0.
What security risk does CVE-2023-50313 pose?
CVE-2023-50313 poses a security risk by potentially allowing weaker TLS configurations for outbound connections.
Is there a patch available for CVE-2023-50313?
Yes, IBM has released guidance on how to mitigate the issues related to CVE-2023-50313.