Multiple vulnerabilities were identified in IBM WebSphere Products. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure and remote code execution on the targeted system. Impact Denial of Service Elevation of Privilege Remote Code Execution Information Disclosure Cross-Site Scripting Security Restriction Bypass System / Technologies affected IBM WebSphere Application Server version 8.5, 9.0 IBM WebSphere Application Server - Liberty version 17.0.0.3 - 26.0.0.8 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://www.ibm.com/support/pages/node/7281625 https://www.ibm.com/support/pages/node/7281628 https://www.ibm.com/support/pages/node/7281631 https://www.ibm.com/support/pages/node/7281633 https://www.ibm.com/support/pages/node/7281641 https://www.ibm.com/support/pages/node/7281648 https://www.ibm.com/support/pages/node/7281649 https://www.ibm.com/support/pages/node/7281651 https://www.ibm.com/support/pages/node/7281721
Multiple vulnerabilities in IBM WebSphere Application Server versions 8.5 and 9.0, and Liberty versions 17.0.0.3 through 26.0.0.8, allow remote attackers to trigger cross-site scripting, denial of service, privilege escalation, information disclosure, and remote code execution. The remediation requires applying specific fixes provided by IBM, with links to multiple security bulletins for the affected versions.