IBM Support

How to Upgrade WAS Liberty from 16.0.0.x / 18.0.0.x to 19.0.0.12 for Log Analysis - Liberty Vulnerability fixes

Troubleshooting


Problem

List of WAS Liberty vulnerabilities which requires Liberty Upgrade to fix the following vulnerabilities:
CVE-2019-12402 : "Abstract - WebSphere Application Server Liberty is affected by Apache Commons Compress vulnerability
CVE-2014-3603  : "Abstract - Man in the middle vulnerability CVE-2014-3603 affects Websphere Liberty and OpenLiberty
CVE-2019-4304  : "Abstract - Bypass security restrictions in WAS Liberty
CVE-2019-4441  : "Abstract - Stack is displayed in WebSphere Application Server   

Document Location

Worldwide

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSPFMY","label":"IBM Operations Analytics - Log Analysis"},"Component":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"1.3.5.1,1.3.5.2,1.3.5.3,1.3.6.0","Edition":"","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
22 June 2026

UID

ibm11135185