VID |
22611 |
Severity |
30 |
Port |
8880, ... |
Protocol |
TCP |
Class |
WWW |
Detailed Description |
IBM WebSphere Application Server 8.0 before Fix Pack 8 appears to be running on the remote host. It is, therefore, potentially affected by the following vulnerabilities :
- A CSRF vulnerability exists in IBM WebSphere Application Server due to improper validation of portlets in the Administrative console. (CVE-2013-0460, PM72275)
- A privilege escalation vulnerability exists on IBM WebSphere Application Servers using WS-Security that are configured for XML Digital Signature using trust store. (CVE-2013-4053, PM90949, PM91521)
- An XSS vulnerability exists in IBM WebSphere Application Server caused by a failure to sanitize user-supplied input in the UDDI Administrative console. (CVE-2013-4052, PM91892)
- A privilege escalation vulnerability exists in IBM WebSphere Application Servers that have been migrated from version 6.1 or later. (CVE-2013-5414, PM92313)
- An XSS vulnerability exists in IBM WebSphere Application Server due to a failure to sanitize application HTTP response data. (CVE-2013-5417, PM93323, PM93944)
- An XSS vulnerability exists in IBM WebSphere Application Server due to a failure to sanitize user-supplied input in the Administrative console. (CVE-2013-5418, PM96477)
- An XSS vulnerability exists in IBM WebSphere Application Server due to a failure to sanitize user-supplied input in the Administrative console. (CVE-2013-6725, PM98132)
- A denial of service vulnerability exists in IBM WebSphere Application Server due to a failure to properly handle requests by a web services endpoint. (CVE-2013-6325, PM99450)
- An information disclosure vulnerability exists in the IBM SDK for Java that ships with IBM WebSphere Application Server related to JSSE. (CVE-2013-5780)
- A denial of service vulnerability exists in the IBM SDK for Java that ships with IBM WebSphere Application Server related to XML. (CVE-2013-5372)
- A denial of service vulnerability exists in the IBM SDK for Java that ships with IBM WebSphere Application Server related to JSSE. (CVE-2013-5803) * Note: This check solely relied on the banner of the remote Web server to assess this vulnerability, so this might be a false positive.
* References: https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_potential_security_vulnerabilites_fixed_in_ibm_websphere_application_server_8_0_0_8?lang=en_us https://www-304.ibm.com/support/docview.wss?uid=swg21661325 https://www-304.ibm.com/support/docview.wss?uid=swg21655990
* Platforms Affected: IBM WebSphere Application Server versions 8.0 prior to 8.0 Fix Pack 8 |
Recommendation |
Upgrade to the latest version of IBM WebSphere Application Server 8.0.0.8 or later, available from the IBM Support & downloads Web site at https://www-304.ibm.com/support/docview.wss?rs=180&uid=swg27004980#ver80 |
Related URL |
CVE-2013-0460,CVE-2013-4052,CVE-2013-4053,CVE-2013-5372,CVE-2013-5414,CVE-2013-5417,CVE-2013-5418,CVE-2013-5780,CVE-2013-5803,CVE-2013-6325 (CVE) |
Related URL |
53676,59826,61129,61901,62336,62338,63082,63115,63224,63778,63780,63781,65096,65099,65100 (SecurityFocus) |
Related URL |
(ISS) |
|