漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
WebSphere Application Server Remote Code Execution
Vulnerability Description
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution and denial of service in the WebSphere Web Server Plug-in component. This vulnerability can be exploited when an attacker impersonates the application server and sends crafted responses to the plug-in.
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
IBM i 代码注入漏洞
Vulnerability Description
IBM i是美国IBM公司的一个国产服务器操作系统。 IBM i 7.6版本、7.5版本、7.4版本和7.3版本存在代码注入漏洞,该漏洞源于WebSphere Web Server Plug-in组件问题,可能导致攻击者冒充应用服务器发送特制响应,从而实现远程代码执行和拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A