Session Fixation in IBM WebSphere Application Server Liberty - CVE-2019-4304
Published: June 14, 2023
Vulnerability identifier: #VU77311
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-4304
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass security restrictions.
The vulnerability exists due to excessive data output by the application. A remote user can bypass security restrictions.
Affected software
IBM WebSphere Application Server Liberty
IBM Cloud Transformation Advisor
Watson Speech Services
IBM Cloud Transformation Advisor
Watson Speech Services
How to mitigate CVE-2019-4304
Install updates from vendor's website.
IBM WebSphere Application Server Liberty - update to 19.0.0.10
IBM Cloud Transformation Advisor - update to 2.0.3
Watson Speech Services - update to 1.1.1
IBM Cloud Transformation Advisor - update to 2.0.3
Watson Speech Services - update to 1.1.1