CVE-2023-35890
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Jul 7, 2023
Updated: Jul 12, 2023
CWE ID 327
Summary
CVE-2023-35890 is a vulnerability affecting IBM WebSphere Application Server versions 8.5 and 9.0. The issue stems from improper encoding in a local configuration file, leading to weaker than expected security. IBM X-Force has assigned the ID 258637 to this vulnerability. This configuration file flaw can potentially be exploited by attackers for unspecified malicious purposes, emphasizing the importance of prompt patching for affected systems. IBM urges users to apply the available security updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- IBM WebSphere Application Server
Affected Vendors
- IBM Corporation