Korean
<< Back
VID 22611
Severity 30
Port 8880, ...
Protocol TCP
Class WWW
Detailed Description IBM WebSphere Application Server 8.0 before Fix Pack 8 appears to be running on the remote host. It is, therefore, potentially affected by the following vulnerabilities :

- A CSRF vulnerability exists in IBM WebSphere Application Server due to improper validation of portlets in the Administrative console. (CVE-2013-0460, PM72275)

- A privilege escalation vulnerability exists on IBM WebSphere Application Servers using WS-Security that are configured for XML Digital Signature using trust store. (CVE-2013-4053, PM90949, PM91521)

- An XSS vulnerability exists in IBM WebSphere Application Server caused by a failure to sanitize user-supplied input in the UDDI Administrative console. (CVE-2013-4052, PM91892)

- A privilege escalation vulnerability exists in IBM WebSphere Application Servers that have been migrated from version 6.1 or later. (CVE-2013-5414, PM92313)

- An XSS vulnerability exists in IBM WebSphere Application Server due to a failure to sanitize application HTTP response data. (CVE-2013-5417, PM93323, PM93944)

- An XSS vulnerability exists in IBM WebSphere Application Server due to a failure to sanitize user-supplied input in the Administrative console. (CVE-2013-5418, PM96477)

- An XSS vulnerability exists in IBM WebSphere Application Server due to a failure to sanitize user-supplied input in the Administrative console. (CVE-2013-6725, PM98132)

- A denial of service vulnerability exists in IBM WebSphere Application Server due to a failure to properly handle requests by a web services endpoint. (CVE-2013-6325, PM99450)

- An information disclosure vulnerability exists in the IBM SDK for Java that ships with IBM WebSphere Application Server related to JSSE. (CVE-2013-5780)

- A denial of service vulnerability exists in the IBM SDK for Java that ships with IBM WebSphere Application Server related to XML. (CVE-2013-5372)

- A denial of service vulnerability exists in the IBM SDK for Java that ships with IBM WebSphere Application Server related to JSSE. (CVE-2013-5803)

* Note: This check solely relied on the banner of the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_potential_security_vulnerabilites_fixed_in_ibm_websphere_application_server_8_0_0_8?lang=en_us
https://www-304.ibm.com/support/docview.wss?uid=swg21661325
https://www-304.ibm.com/support/docview.wss?uid=swg21655990

* Platforms Affected:
IBM WebSphere Application Server versions 8.0 prior to 8.0 Fix Pack 8
Recommendation Upgrade to the latest version of IBM WebSphere Application Server 8.0.0.8 or later, available from the IBM Support & downloads Web site at https://www-304.ibm.com/support/docview.wss?rs=180&uid=swg27004980#ver80
Related URL CVE-2013-0460,CVE-2013-4052,CVE-2013-4053,CVE-2013-5372,CVE-2013-5414,CVE-2013-5417,CVE-2013-5418,CVE-2013-5780,CVE-2013-5803,CVE-2013-6325 (CVE)
Related URL 53676,59826,61129,61901,62336,62338,63082,63115,63224,63778,63780,63781,65096,65099,65100 (SecurityFocus)
Related URL (ISS)