CVE-2024-56339: IBM WebSphere Application Server information disclosure
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.
Other sources
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7to a version that resolves this vulnerability.Fixed in 25.0.0.8 - Upgrade
Upgrade
IBM WebSphere Application Server 9.0 (traditional) v9.0.0.0 through 9.0.5.24to a version that resolves this vulnerability.Fixed in 9.0.5.26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH64682 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH64683
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56339?
CVE-2024-56339 has a critical severity rating due to its potential to allow remote attackers to bypass security restrictions.
How do I fix CVE-2024-56339?
To address CVE-2024-56339, it is recommended to update IBM WebSphere Application Server and WebSphere Application Server Liberty to the latest versions provided by IBM.
Who is affected by CVE-2024-56339?
CVE-2024-56339 affects users of IBM WebSphere Application Server version 9.0 and IBM WebSphere Application Server Liberty versions 17.0.0.3 through 25.0.0.7.
What are the potential impacts of CVE-2024-56339?
The potential impact of CVE-2024-56339 includes unauthorized access and the ability for attackers to execute actions that should be restricted.
When was CVE-2024-56339 disclosed?
CVE-2024-56339 was disclosed in 2024, highlighting a security configuration vulnerability in select IBM WebSphere products.