No analysis available yet.
Vendor Solution
For IBM WebSphere Application Server Liberty 17.0.0.3 - 25.0.0.7 using the servlet-3.1, servlet-4.0, servlet-5.0 or servlet-6.0 feature: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH64682 --OR-- · Apply Fix Pack 25.0.0.8 or later (targeted availability 3Q2025). For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.24: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH64683 --OR-- · Apply Fix Pack 9.0.5.26 or later (targeted availability 4Q2025). Additional interim fixes may be available and linked off the interim fix download page.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54856 | IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7239955 |
|
Thu, 14 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:* cpe:2.3:a:ibm:websphere_application_server:9.0.0.0:*:*:*:-:*:*:* |
Thu, 07 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 Aug 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm
Ibm websphere Application Server |
|
| CPEs | cpe:2.3:a:ibm:websphere_application_server:17.0.0.3:*:*:*:liberty:*:*:* cpe:2.3:a:ibm:websphere_application_server:25.0.0.7:*:*:*:liberty:*:*:* cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm websphere Application Server |
Thu, 07 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration. | |
| Title | IBM WebSphere Application Server information disclosure | |
| Weaknesses | CWE-650 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-07T16:29:34.336Z
Reserved: 2024-12-20T13:55:07.212Z
Link: CVE-2024-56339
Updated: 2025-08-07T16:29:31.252Z
Status : Analyzed
Published: 2025-08-07T16:15:29.897
Modified: 2025-08-14T20:02:02.473
Link: CVE-2024-56339
No data.
OpenCVE Enrichment
No data.
EUVD