CVE-2023-50315
IBM WebSphere Application Server vulnerability analysis and mitigation

Overview

IBM WebSphere Application Server versions 8.5 and 9.0 contain a vulnerability that could allow an attacker with network access to conduct spoofing attacks. This vulnerability was assigned CVE-2023-50315 and was disclosed on August 14, 2024. The vulnerability affects IBM WebSphere Application Server versions 8.5.0.0 and 9.0.0.0 (NVD, CVE).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 5.9 (Medium) by NIST with a vector string of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. IBM Corporation assessed it with a slightly lower CVSS score of 5.3 (Medium) with vector string CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. The vulnerability is classified under CWE-295 (Improper Certificate Validation) (NVD).

Impact

An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. The vulnerability primarily affects the confidentiality of the system, with potential for high impact on information disclosure (IBM Advisory).

Mitigation and workarounds

IBM recommends addressing the vulnerability by applying currently available interim fix or fix pack containing APAR PH58798. For version 9.0.0.0 through 9.0.5.20, users should either upgrade to minimal fix pack levels and apply Interim Fix PH58798 or apply Fix Pack 9.0.5.21 or later (targeted for 3Q2024). For version 8.5.0.0 through 8.5.5.26, users should either upgrade to minimal fix pack levels and apply Interim Fix PH58798 or apply Fix Pack 8.5.5.27 or later (targeted for 1Q2025) (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere Application Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-36047HIGH7.5
  • IBM WebSphere Application ServerIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesAug 14, 2025
CVE-2025-33142HIGH7.5
  • IBM WebSphere Application ServerIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesAug 14, 2025
CVE-2025-12635MEDIUM5.4
  • IBM WebSphere Application ServerIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesDec 08, 2025
CVE-2025-36099MEDIUM4.9
  • IBM WebSphere Application ServerIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesSep 29, 2025
CVE-2025-36000MEDIUM4.8
  • IBM WebSphere Application ServerIBM WebSphere Application Server
  • cpe:2.3:a:ibm:websphere_application_server
NoYesAug 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management