Vulnerability identifier: #VU60870
Vulnerability risk: Low
CVSSv3.1: 3.7 [CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-451
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
IBM WebSphere Application Server
Server applications /
Application servers
IBM WebSphere Application Server Liberty
Server applications /
Application servers
Vendor: IBM Corporation
Description
The vulnerability allows a remote attacker to perform clickjacking attack.
The vulnerability exists due to incorrect processing of user-supplied data, when REST API discovery is configured through the WebSphere administrative console Web Container settings to enable the API Discovery service, or through IBM WebSphere Application Server Liberty features mpOpenAPI-1.0, mpOpenAPI-1.1, mpOpenAPI-2.0, apiDiscovery-1.0, openapi-3.0 or openapi-3.1. A remote attacker can perform clickjacking attack.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
IBM WebSphere Application Server: 9.0 - 9.0.5.10
IBM WebSphere Application Server Liberty: 17.0.0.3 - 22.0.0.2
External links
http://www.ibm.com/support/pages/node/6559044
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.