Reliance on Cookies without Validation and Integrity Checking in IBM WebSphere Application Server Liberty - CVE-2019-4305
Published: June 14, 2023
Vulnerability identifier: #VU77287
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-4305
CWE-ID: CWE-565
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the improper setting of a cookie. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
IBM WebSphere Application Server Liberty
IBM Cloud Transformation Advisor
Watson Speech Services
IBM Cloud Transformation Advisor
Watson Speech Services
How to mitigate CVE-2019-4305
Install updates from vendor's website.
IBM WebSphere Application Server Liberty - update to 19.0.0.10
IBM Cloud Transformation Advisor - update to 2.0.3
Watson Speech Services - update to 1.1.1
IBM Cloud Transformation Advisor - update to 2.0.3
Watson Speech Services - update to 1.1.1