- Description
- IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
- Products
- websphere_application_server
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@us.ibm.com
- CWE-470
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:-:*:*:*:liberty:*:*:*",
"matchCriteriaId": "7E0B3D5C-C912-4874-AD3D-62B6E6EBE742",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:8.5.0.0:*:*:*:-:*:*:*",
"matchCriteriaId": "03A3AC1C-36F7-4CED-973B-C0897EC775FD",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ibm:websphere_application_server:9.0.0.0:*:*:*:-:*:*:*",
"matchCriteriaId": "E79B1229-6DC0-4461-B814-1F671AE0A090",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]