IBM WebSphere Application Server Liberty
cpe:2.3:a:ibm:websphere_application_server_liberty:*:*:*:*:*:*:*
- >= 17.0.0.3, <= 26.0.0.3
A server-side request forgery (SSRF) vulnerability has been identified in IBM WebSphere Application Server Liberty versions 17.0.0.3 prior to 26.0.0.3, with the samlWeb-2.0 feature enabled. This vulnerability allows remote attackers to send unauthorized requests from the server, which could lead to network enumeration or facilitate other types of attacks.
Exploitation of this vulnerability could allow remote attackers to send unauthorized requests from the server, potentially leading to network enumeration or other attacks.
Users are advised to upgrade to IBM WebSphere Application Server Liberty Fix Pack 26.0.0.4 or later, or to apply the Interim Fix that resolves APAR PH70017. Additional interim fixes may be available and linked off the interim fix download page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.