CVE-2024-35154

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to the administrative console, to execute arbitrary code. Using specially crafted input, the attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 292641.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:19

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/292641 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/292641 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7159825 - Vendor Advisory () https://www.ibm.com/support/pages/node/7159825 - Vendor Advisory

20 Sep 2024, 17:46

Type Values Removed Values Added
CWE NVD-CWE-Other
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/292641 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/292641 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7159825 - () https://www.ibm.com/support/pages/node/7159825 - Vendor Advisory
First Time Ibm websphere Application Server
Ibm
CPE cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*

11 Jul 2024, 13:05

Type Values Removed Values Added
Summary
  • (es) IBM WebSphere Application Server 8.5 y 9.0 podría permitir que un atacante remoto autenticado, que haya autorizado acceso a la consola administrativa, ejecute código arbitrario. Utilizando entradas especialmente manipuladas, el atacante podría aprovechar esta vulnerabilidad para ejecutar código arbitrario en el sistema. ID de IBM X-Force: 292641.

09 Jul 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 22:15

Updated : 2024-11-21 09:19


NVD link : CVE-2024-35154

Mitre link : CVE-2024-35154

CVE.ORG link : CVE-2024-35154


JSON object : View

Products Affected

ibm

  • websphere_application_server
CWE
CWE-250

Execution with Unnecessary Privileges

NVD-CWE-Other