CVE-2024-35154

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*

History

20 Sep 2024, 17:46

Type Values Removed Values Added
References () https://www.ibm.com/support/pages/node/7159825 - () https://www.ibm.com/support/pages/node/7159825 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/292641 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/292641 - VDB Entry, Vendor Advisory
CWE CWE-250 NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
First Time Ibm
Ibm websphere Application Server
CPE cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*

09 Jul 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 22:15

Updated : 2024-09-20 17:46


NVD link : CVE-2024-35154

Mitre link : CVE-2024-35154


JSON object : View

Products Affected

ibm

  • websphere_application_server