CVE-2023-46158: IBM WebSphere Application Server session fixation
Published Oct 24, 2023
·Updated
IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.
Other sources
IBM WebSphere Application Server Liberty could provide weaker than expected security due to improper resource expiration handling.
— IBM
Affected Software
2 affected components
IBM WebSphere Application Server Liberty<=23.0.0.9 - 23.0.0.10
IBM WebSphere Application Server Liberty>=23.0.0.9<23.0.0.11
Event History
Oct 24, 2023
CVE Published
via IBM·12:00 AM
Oct 25, 2023
CVE Published
via MITRE·02:56 AM
Data Sourced
via MITRE·02:56 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2023-46158.
2
What is the severity rating of CVE-2023-46158?
CVE-2023-46158 has a severity rating of medium (4.9).
3
What is the affected software for CVE-2023-46158?
The affected software for CVE-2023-46158 is IBM WebSphere Application Server Liberty version 23.0.0.9 through 23.0.0.10.
4
What is the CWE category associated with CVE-2023-46158?
The CWE category associated with CVE-2023-46158 is CWE-613.
5
How can I fix the vulnerability in IBM WebSphere Application Server Liberty?
To fix the vulnerability in IBM WebSphere Application Server Liberty, update to a version beyond 23.0.0.10.