IBM Support

PH35098:Directory Traversal vulnerability in WebSphere Application Server ND (CVE-2021-20517 CVSS 6.4)

Download


Downloadable File

File link File size File description

Abstract

Directory Traversal vulnerability in WebSphere Application Server ND (CVE-2021-20517 CVSS 6.4)

Download Description

PH35098 resolves the following problem:

ERROR DESCRIPTION:
Directory Traversal vulnerability in WebSphere Application Server ND (CVE-2021-20517 CVSS 6.4)

PROBLEM SUMMARY:
Directory Traversal vulnerability in WebSphere Application Server ND (CVE-2021-20517 CVSS 6.4)

PROBLEM CONCLUSION:
Confidential for CVE-2021-20517.

The fix for this APAR is currently targeted for inclusion
in fix packs 8.5.5.20 and 9.0.5.8.

Please refer to the Recommended Updates page for delivery information:
http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980

Prerequisites

None

Installation Instructions

Review the readme.txt for detailed installation instructions.

URL SIZE(Bytes)
V90 Readme 2269
V85 Readme 2377

Download Package

 
IMPORTANT NOTE:
WebSphere Application Server and Liberty fix access requires S&S Entitlement in 2021, use properly registered IDs to download fixes for WebSphere Application Server below. 
DOWNLOAD RELEASE DATE SIZE(Bytes)
APPLICABLE fix pack(s)

DOWNLOAD Options

What is Fix Central(FC)?

9.0.0.0-WS-WASND-IFPH35098 25 May 2021 475070 9.0.0.0 through 9.0.5.7 FC
8.5.0.0-WS-WASND-IFPH35098 25 May 2021 480559 8.5.0.0 through 8.5.5.19 FC

Problems Solved

PH35098

On

Technical Support

Contact IBM Support at https://www.ibm.com/software/mysupport/s/ or 1-800-IBM-SERV (US only).

Document Location

Worldwide

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Component":"General","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF012","label":"IBM i"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"9.0.5.7;9.0.5.6;9.0.5.5;9.0.5.4;9.0.5.3;9.0.5.2;9.0.5.1;9.0.5.0;9.0.0.11;9.0.0.10;9.0.0.9;9.0.0.8;9.0.0.7;9.0.0.6;9.0.0.5;9.0.0.4;9.0.0.3;9.0.0.2;9.0.0.1;9.0.0.0;8.5.5.19;8.5.5.18;8.5.5.17;8.5.5.16;8.5.5.8;8.5.5.7;8.5.5.6;8.5.5.5;8.5.5.4;8.5.5.3;8.5.5.2;8.5.5.1;8.5.5;8.5.0.2;8.5.0.1;8.5;8.5.5.15;8.5.5.14;8.5.5.13;8.5.5.12;8.5.5.11;8.5.5.10;8.5.5.9","Edition":"Base","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
27 May 2021

UID

ibm16456301