CVE-2024-35154

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*

History

20 Sep 2024, 17:46

Type Values Removed Values Added
First Time Ibm
Ibm websphere Application Server
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/292641 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/292641 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7159825 - () https://www.ibm.com/support/pages/node/7159825 - Vendor Advisory
CPE cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*
CWE NVD-CWE-Other

11 Jul 2024, 13:05

Type Values Removed Values Added
Summary
  • (es) IBM WebSphere Application Server 8.5 y 9.0 podría permitir que un atacante remoto autenticado, que haya autorizado acceso a la consola administrativa, ejecute código arbitrario. Utilizando entradas especialmente manipuladas, el atacante podría aprovechar esta vulnerabilidad para ejecutar código arbitrario en el sistema. ID de IBM X-Force: 292641.

09 Jul 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 22:15

Updated : 2024-09-20 17:46


NVD link : CVE-2024-35154

Mitre link : CVE-2024-35154

CVE.ORG link : CVE-2024-35154


JSON object : View

Products Affected

ibm

  • websphere_application_server
CWE
NVD-CWE-Other CWE-250

Execution with Unnecessary Privileges