Information disclosure in IBM WebSphere Application Server Liberty - CVE-2023-50314
Published: August 15, 2024 / Updated: December 23, 2024
Vulnerability identifier: #VU96058
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50314
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can use a certificate issued by a trusted authority to obtain sensitive information.
Affected software
IBM WebSphere Application Server Liberty
IBM WebSphere Application Server
Voice Gateway
IBM Cloud Pak for Security
IBM Process Mining
IBM Cloud Transformation Advisor
IBM SPSS Analytic Server
IBM Sterling B2B Integrator
IBM Tivoli Netcool Impact
IBM Spectrum Symphony
IBM TXSeries for Multiplatforms
WebSphere Remote Server
IBM Common Licensing
IBM Transformation Extender Advanced
IBM Cloud Application Business Insights
Financial Transaction Manager for Digital Payments (DP)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM MQ
IBM Security Verify Governance - Containerized Identity Manager
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM Business Automation Workflow
QRadar Suite
IBM Cloud Pak System
Data Product Hub
Storage Protect for Space Management
IBM OpenPages with Watson
Maximo Application Suite - Predict Component
CICS Transaction Gateway for Multiplatforms
Business Automation Insights
PowerVM NovaLink
Storage Protect Operations Center
Maximo Application Suite - Monitor Component
IBM Virtualization Engine TS7700 3948-VED
Robotic Process Automation for Cloud Pak
IBM i
IBM Tivoli Application Dependency Discovery Manager
IBM CICS TX Advanced
IBM CICS TX Standard
Planning Analytics Local
IBM Cognos Analytics
IBM Storage Scale System
IBM Spectrum Protect Backup-Archive Client
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
Virtualization Engine TS7700 3957-VED
IBM License Metric Tool
IBM WebSphere Application Server
Voice Gateway
IBM Cloud Pak for Security
IBM Process Mining
IBM Cloud Transformation Advisor
IBM SPSS Analytic Server
IBM Sterling B2B Integrator
IBM Tivoli Netcool Impact
IBM Spectrum Symphony
IBM TXSeries for Multiplatforms
WebSphere Remote Server
IBM Common Licensing
IBM Transformation Extender Advanced
IBM Cloud Application Business Insights
Financial Transaction Manager for Digital Payments (DP)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite
IBM MQ
IBM Security Verify Governance - Containerized Identity Manager
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM Business Automation Workflow
QRadar Suite
IBM Cloud Pak System
Data Product Hub
Storage Protect for Space Management
IBM OpenPages with Watson
Maximo Application Suite - Predict Component
CICS Transaction Gateway for Multiplatforms
Business Automation Insights
PowerVM NovaLink
Storage Protect Operations Center
Maximo Application Suite - Monitor Component
IBM Virtualization Engine TS7700 3948-VED
Robotic Process Automation for Cloud Pak
IBM i
IBM Tivoli Application Dependency Discovery Manager
IBM CICS TX Advanced
IBM CICS TX Standard
Planning Analytics Local
IBM Cognos Analytics
IBM Storage Scale System
IBM Spectrum Protect Backup-Archive Client
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V
Virtualization Engine TS7700 3957-VED
IBM License Metric Tool
How to mitigate CVE-2023-50314
Install updates from vendor's website.
Voice Gateway - addressed in versions 1.0.8.14, 1.0.8.17
QRadar Suite - addressed in versions 1.10.26.0, 1.10.27.0
IBM Process Mining - update to 2.0
IBM Cloud Transformation Advisor - update to 3.10.2
IBM Cloud Pak System - update to 2.3.6.1
Data Product Hub - update to 5.1.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM Spectrum Symphony - update to 7.3.2 FP3
Storage Protect for Space Management - update to 8.1.25.0
Maximo Application Suite - Predict Component - update to 9.0.3
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix34, 11.1.0.0 ifix26
IBM CICS TX Standard - update to 11.1.0.0 ifix27
Business Automation Insights - update to 24.0.0.0.2
IBM Cloud Application Business Insights - addressed in versions 1.1.7.11, 1.1.8.6
Planning Analytics Local - addressed in versions 2.0.0.101, 2.0.9.21, 2.1.8
PowerVM NovaLink - addressed in versions 2.1.1-240913, 2.2.1-240917
Financial Transaction Manager for Digital Payments (DP) - update to 3.2.13
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.7, 5.0.3
IBM Storage Scale System - addressed in versions 5.1.9.7, 5.2.2.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Storage Protect Operations Center - update to 8.1.25
IBM Spectrum Protect Backup-Archive Client - update to 8.1.25.0
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.25.0
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.18
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.19, 8.7.13, 9.0.5
Maximo Application Suite - Monitor Component - addressed in versions 8.10.12, 8.11.9, 9.0.0
IBM Maximo Application Suite - addressed in versions 8.10.18, 8.11.15, 9.0.3
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.54.2.17, 8.60.0.115
Virtualization Engine TS7700 3957-VED - addressed in versions 8.54.2.17, 8.60.0.115
IBM WebSphere Application Server - update to 9.0.5.25
IBM MQ - addressed in versions 9.1.0.24, 9.2.0.28, 9.3.0.25, 9.4.0.6
IBM License Metric Tool - update to 9.2.37
IBM Security Verify Governance - Containerized Identity Manager - update to 11.0.0.0
IBM Cognos Analytics - addressed in versions 11.2.4 IF5, 12.0.4 IF2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.19
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.19
IBM Business Automation Workflow - addressed in versions 24.0.0-IF005, 24.0.1-IF002
QRadar Suite - addressed in versions 1.10.26.0, 1.10.27.0
IBM Process Mining - update to 2.0
IBM Cloud Transformation Advisor - update to 3.10.2
IBM Cloud Pak System - update to 2.3.6.1
Data Product Hub - update to 5.1.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM Spectrum Symphony - update to 7.3.2 FP3
Storage Protect for Space Management - update to 8.1.25.0
Maximo Application Suite - Predict Component - update to 9.0.3
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix34, 11.1.0.0 ifix26
IBM CICS TX Standard - update to 11.1.0.0 ifix27
Business Automation Insights - update to 24.0.0.0.2
IBM Cloud Application Business Insights - addressed in versions 1.1.7.11, 1.1.8.6
Planning Analytics Local - addressed in versions 2.0.0.101, 2.0.9.21, 2.1.8
PowerVM NovaLink - addressed in versions 2.1.1-240913, 2.2.1-240917
Financial Transaction Manager for Digital Payments (DP) - update to 3.2.13
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.7, 5.0.3
IBM Storage Scale System - addressed in versions 5.1.9.7, 5.2.2.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
Storage Protect Operations Center - update to 8.1.25
IBM Spectrum Protect Backup-Archive Client - update to 8.1.25.0
IBM Spectrum Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.25.0
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.18
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.19, 8.7.13, 9.0.5
Maximo Application Suite - Monitor Component - addressed in versions 8.10.12, 8.11.9, 9.0.0
IBM Maximo Application Suite - addressed in versions 8.10.18, 8.11.15, 9.0.3
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.54.2.17, 8.60.0.115
Virtualization Engine TS7700 3957-VED - addressed in versions 8.54.2.17, 8.60.0.115
IBM WebSphere Application Server - update to 9.0.5.25
IBM MQ - addressed in versions 9.1.0.24, 9.2.0.28, 9.3.0.25, 9.4.0.6
IBM License Metric Tool - update to 9.2.37
IBM Security Verify Governance - Containerized Identity Manager - update to 11.0.0.0
IBM Cognos Analytics - addressed in versions 11.2.4 IF5, 12.0.4 IF2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.19
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.19
IBM Business Automation Workflow - addressed in versions 24.0.0-IF005, 24.0.1-IF002
External References
Related Security Bulletins
- Information disclosure in IBM WebSphere Application Server Liberty
- Information disclosure in IBM Transformation Extender Advanced
- Information disclosure in IBM License Metric Tool
- Information disclosure in IBM Watson Discovery
- Multiple vulnerabilities in IBM QRadar Suite Software
- Information disclosure in IBM Maximo Application Suite - Monitor Component
- Information disclosure in IBM MQ
- Information disclosure in IBM PowerVM Novalink
- Information disclosure in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in QRadar Suite Software
- IBM WebSphere Remote Server update for IBM MQ
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- IBM CICS TX Standard update for WebSphere Application Server Liberty
- IBM CICS TX Advanced update for WebSphere Application Server Liberty
- IBM TXSeries for Multiplatforms update for WebSphere Application Server Liberty
- IBM Sterling B2B Integrator update for WebSphere Application Server
- Information disclosure in IBM Financial Transaction Manager for Digital Payments
- Information disclosure in IBM Maximo Application Suite - Predict Component
- Information disclosure in IBM Maximo Application Suite - Manage Component
- Information disclosure in IBM Common Licensing
- IBM Robotic Process Automation for Cloud Pak update for IBM WebSphere Application Server Liberty
- Multiple vulnerabilities in IBM Storage Scale
- Multiple vulnerabilities in IBM Data Product Hub
- IBM Storage Protect Operations Center update for IBM WebSphere Application Server Liberty
- CICS Transaction Gateway for Multiplatforms update for IBM WebSphere Application Server Liberty
- Information disclosure in IBM Storage Protect for Space Management
- IBM Storage Protect for Virtual Environments: Data Protection for Hyper-V update for WebSphere Application Server Liberty
- IBM Spectrum Protect Backup-Archive Client update for WebSphere Application Server Liberty
- Information disclosure in IBM OpenPages with Watson
- Information disclosure in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM SPSS Analytic Server
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Security Verify Governance Identity Manager Container
- Multiple vulnerabilities in IBM Business Automation Insights
- Information disclosure in IBM Cloud Application Business Insights
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in IBM Cloud Application Performance Management (APM)
- IBM i update for IBM WebSphere Application Server Liberty
- IBM System Storage Virtualization Engine TS7700 update for IBM WebSphere Application Server Liberty
- Multiple vulnerabilities in IBM Planning Analytics
- IBM Tivoli Application Dependency Discovery Manager update for IBM WebSphere Application Server Liberty
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM Spectrum Symphony
- Multiple vulnerabilities in IBM Cloud Pak System