IBM WebSphere Application Server
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*, +1 more
- 9.0
- 8.5
A vulnerability exists in IBM WebSphere Application Server versions 8.5 and 9.0, where TLS connections may not be as secure as expected. This issue is related to improper certificate validation, potentially leading to weaker encryption or authentication in TLS communications.
This vulnerability could allow for man-in-the-middle attacks, where an attacker could intercept or alter communications between the client and server, taking advantage of the weaker TLS security.
Users are advised to upgrade to IBM WebSphere Application Server Fix Pack 9.0.5.25 or later, or Fix Pack 8.5.5.29 or later. Interim fixes resolving this vulnerability are also available for both versions. Additional interim fixes may be linked off the interim fix download page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.