Download
Downloadable File
| File link | File size | File description |
|---|---|---|
Abstract
PH60195: IBM WebSphere Application Server is vulnerable to a denial of service due to jose4j (CVE-2023-51775 CVSS 7.5)
Download Description
This fix has been superseded by a fix for another APAR. For information on how to obtain the latest OpenID Connect runtime that includes this APAR, see the technote Obtaining WebSphere OpenID Connect (OIDC) latest version.
PH60195 resolves the following problem:
ERROR DESCRIPTION:
ERROR DESCRIPTION:
IBM WebSphere Application Server is vulnerable to a denial of service due to jose4j (CVE-2023-51775 CVSS 7.5)
PROBLEM CONCLUSION:
Confidential for CVE-2023-51775.
The fix forPH60195 is targeted for inclusion in fix pack 8.5.5.26 and 9.0.5.20. Refer to the Recommended Updates page for delivery information: http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
This fix has been superseded by a fix for another APAR. For information on how to obtain the latest OpenID Connect runtime that includes this APAR, see the technote Obtaining WebSphere OpenID Connect (OIDC) latest version.
Problems Solved
PH60195
Change History
19 April 2024: Remove the link to the v8.5.5 fix for this APAR.
25 April 2024: Remove the link to the v9.0 fix for PH60195. Add links for PH61002.
07 May 2024: Fix the APAR number in the title.
22 January 2026: Remove fixes. This fix is superseded by OIDC 1.5.4
Off
Document Location
Worldwide
[{"Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"ARM Category":[{"code":"a8m50000000CdESAA0","label":"Security-\u003ESSO-\u003EOpenId Connect"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.5.5;9.0.0;9.0.5"}]
Was this topic helpful?
Document Information
Modified date:
25 February 2026
UID
ibm17145188