#VU23677 Improper access control in WebSphere Deployer - CVE-2019-16559

 

#VU23677 Improper access control in WebSphere Deployer - CVE-2019-16559

Published: December 18, 2019


Vulnerability identifier: #VU23677
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-16559
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
WebSphere Deployer
Software vendor:
Jenkins

Description

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the affected software does not perform permission checks in methods performing form validation. A remote user with Overall/Read access can perform connection tests, determine whether files with an attacker-specified path exist on the Jenkins master file system, and obtain limited information about the Jenkins and plugin configuration based on the responses.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links