CVE-2023-50312

Severity
6.5MEDIUM
EPSS
0.0%
top 90.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1

Description

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274711.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/websphere_application_server_liberty17.0.0.324.0.0.2
NVDibm/websphere_application_server17.0.0.324.0.0.3

🔴Vulnerability Details

2
CVEList
IBM WebSphere Application Server Liberty information disclosure2024-03-01
GHSA
GHSA-65xh-f2p9-7f43: IBM WebSphere Application Server Liberty 172024-03-01
CVE-2023-50312 (MEDIUM CVSS 6.5) | IBM WebSphere Application Server Li | cvebase.io