IBM WebSphere Application Server Liberty是美国国际商业机器(IBM)公司的一款构建于Open Liberty项目之上的Java应用程序服务器。 IBM WebSphere Application Server Liberty 17.0.0.3至26.0.0.1版本存在路径遍历漏洞,该漏洞源于特权用户可以上传包含路径遍历序列的zip归档文件,可能导致覆盖文件并执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | WebSphere Application Server Liberty | 17.0.0.3 ~ 26.0.0.1 |
cpe:2.3:a:ibm:websphere_application_server:17.0.0.3:*:*:*:liberty:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-13096 | 7.1 HIGH | XML eXternal Entity injection (XXE) vulnerability affect IBM Business Automation Workflow |
| CVE-2025-36436 | 6.4 MEDIUM | Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation |
| CVE-2025-36238 | 6.0 MEDIUM | Power System Exposure of Sensitive System Information |
| CVE-2025-36253 | 5.9 MEDIUM | Multiple Vulnerabilities in IBM Concert Software. |
| CVE-2025-15395 | 4.3 MEDIUM | IBM Jazz Foundation access control violation |
| CVE-2025-36194 | 2.8 LOW | This Power System update is being released to address |
No comments yet