IBM Support

Security Bulletin: Multiple Security Vulnerabilities fixed in IBM WebSphere Application Server 8.5.5.9

Security Bulletin


Summary

Cross reference list for security vulnerabilities fixed in IBM WebSphere Application Server, IBM WebSphere Application Server Hypervisor, WebSphere Application Server Liberty Profile and IBM HTTP Server.

Affected Products and Versions

The following IBM WebSphere Application Server Versions are affected:

  • Version 8.5.5 Full Profile and Liberty Profile
  • Version 8.5
  • Version 8
  • Version 7

Remediation/Fixes

Refer to Security bulletins already published: vulnerabilities


PI49272 Cross-site scripting vulnerability in IBM WebSphere Application Server
PI50993 Apache HTTPComponents vulnerabilities in IBM WebSphere Application Server
PI52395 and PI54962 Vulnerabilities in GSKit component used by IBM HTTP Server
PI58003 Cross-site scripting vulnerability in IBM WebSphere Application Server

If you are using a Docker image built on the websphere-liberty image from Docker Hub, ensure that you are building on a version containing Fix Pack 9 (8.5.5.9), or later. You can use the command "productInfo version" to determine the version contained in an image, for example "docker run websphere-liberty productInfo version".

Get Notified about Future Security Bulletins

References

Off

Change History

18 March 2016: original document published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"--","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF012","label":"IBM i"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"8.5.5;8.5;8.0;7.0","Edition":"Base;Developer;Express;Liberty;Network Deployment","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
15 June 2018

UID

swg21979087