Buffer overflow in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - CVE-2016-0385
Published: January 29, 2024
Vulnerability identifier: #VU85878
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0385
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability occurs when HttpSessionIdReuse is enabled. A remote user can create a specially crafted data, trigger memory corruption and gain access to sensitive information.
Affected software
IBM WebSphere Application Server
IBM WebSphere Application Server Liberty
IBM WebSphere Application Server Liberty
How to mitigate CVE-2016-0385
Install updates from vendor's website.
IBM WebSphere Application Server - addressed in versions 7.0.0.43, 8.0.0.13, 8.5.5.10, 9.0.0.1
IBM WebSphere Application Server Liberty - update to 16.0.0.3
IBM WebSphere Application Server Liberty - update to 16.0.0.3