Information disclosure in IBM WebSphere Application Server Liberty - CVE-2023-50314
Published: August 15, 2024 / Updated: December 23, 2024
Vulnerability identifier: #VU96058
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-50314
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Affected software:
IBM WebSphere Application Server Liberty
IBM WebSphere Application Server
Voice Gateway
IBM Cloud Pak for Security
IBM Process Mining
IBM Cloud Transformation Advisor
IBM SPSS Analytic Server
IBM Sterling B2B Integrator
IBM Tivoli Netcool Impact
IBM Spectrum Symphony
IBM TXSeries for Multiplatforms
WebSphere Remote Server
IBM Common Licensing
IBM Transformation Extender Advanced
IBM Cloud Application Business Insights
Financial Transaction Manager for Digital Payments (DP)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM MQ
IBM Security Verify Governance - Containerized Identity Manager
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM Business Automation Workflow
QRadar Suite
IBM Cloud Pak System
Data Product Hub
Storage Protect for Space Management
IBM OpenPages with Watson
Maximo Application Suite - Predict Component
CICS Transaction Gateway for Multiplatforms
Business Automation Insights
PowerVM NovaLink
Storage Protect Operations Center
Maximo Application Suite - Monitor Component
IBM Virtualization Engine TS7700 3948-VED
Robotic Process Automation for Cloud Pak
IBM i
IBM Tivoli Application Dependency Discovery Manager
IBM CICS TX Advanced
IBM CICS TX Standard
Planning Analytics Local
IBM Cognos Analytics
IBM Storage Scale System
IBM Spectrum Protect Backup-Archive Client
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
Virtualization Engine TS7700 3957-VED
IBM License Metric Tool
IBM WebSphere Application Server Liberty
IBM WebSphere Application Server
Voice Gateway
IBM Cloud Pak for Security
IBM Process Mining
IBM Cloud Transformation Advisor
IBM SPSS Analytic Server
IBM Sterling B2B Integrator
IBM Tivoli Netcool Impact
IBM Spectrum Symphony
IBM TXSeries for Multiplatforms
WebSphere Remote Server
IBM Common Licensing
IBM Transformation Extender Advanced
IBM Cloud Application Business Insights
Financial Transaction Manager for Digital Payments (DP)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM MQ
IBM Security Verify Governance - Containerized Identity Manager
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM Business Automation Workflow
QRadar Suite
IBM Cloud Pak System
Data Product Hub
Storage Protect for Space Management
IBM OpenPages with Watson
Maximo Application Suite - Predict Component
CICS Transaction Gateway for Multiplatforms
Business Automation Insights
PowerVM NovaLink
Storage Protect Operations Center
Maximo Application Suite - Monitor Component
IBM Virtualization Engine TS7700 3948-VED
Robotic Process Automation for Cloud Pak
IBM i
IBM Tivoli Application Dependency Discovery Manager
IBM CICS TX Advanced
IBM CICS TX Standard
Planning Analytics Local
IBM Cognos Analytics
IBM Storage Scale System
IBM Spectrum Protect Backup-Archive Client
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
Virtualization Engine TS7700 3957-VED
IBM License Metric Tool
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can use a certificate issued by a trusted authority to obtain sensitive information.
How to mitigate CVE-2023-50314
Install updates from vendor's website.