IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274713.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7165502 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/274713 | vdb entry vendor advisory |