Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-35154


IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.


Published

2024-07-09T22:15:02.227

Last Modified

2024-11-21T09:19:50.140

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-250
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm websphere_application_server ≤ 8.5.5.25 Yes
Application ibm websphere_application_server ≤ 9.0.5.20 Yes

References