IBM Security Bulletin: Potential security vulnerability in the WebSphere Application Server Admin Console (CVE-2017-1501)
Aug 16, 2017 10:00 am EDT
Categorized: Medium Severity
Share this post:
There is a potential security vulnerability in the WebSphere Application Server Admin Console if you have updated the web services security bindings settings. If you changed the cipher suites in the web services security bindings settings they may not have been saved properly and thus be weaker security then you expected. Verify that your settings are what you expect.
CVE(s): CVE-2017-1501
Affected product(s) and affected version(s):
This vulnerability affects the following versions and releases of IBM WebSphere Application Server:
- Version 9.0
- Version 8.5
- Version 8.0
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2vCVX3B
X-Force Database: http://ift.tt/2wPBA21
Archives
from IBM Product Security Incident Response Team http://ift.tt/2vDo6Yq