Input validation error in IBM WebSphere Application Server - CVE-2024-35154

 

Input validation error in IBM WebSphere Application Server - CVE-2024-35154

Published: August 9, 2024


Vulnerability identifier: #VU95625
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-35154
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to insufficient validation of user-supplied input within the administrative console. A remote privileged user can send specially crafted input to the application and execute arbitrary code on the system.


Affected software

IBM WebSphere Application Server
Engineering Test Management
Tivoli Composite Application Manager for Application Diagnostics
Business Monitor
IBM Business Automation Workflow
IBM Tivoli System Automation Application Manager
Jazz for Service Management
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Maximo Asset Management
WebSphere Service Registry and Repository
InfoSphere Master Data Management
IBM Tivoli Monitoring
IBM Security Verify Governance
IBM Cloud Pak System

How to mitigate CVE-2024-35154

Install updates from vendor's website.

IBM WebSphere Application Server - addressed in versions 8.5.5.26, 9.0.5.21
IBM Cloud Pak System - update to 2.3.4.1 iFix 1
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Security Verify Governance - update to 10.0.2.0.4

External References

Related Security Bulletins