IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could exploit this vulnerability using a certificate issued by a trusted authority to obtain sensitive information. IBM X-Force ID: 274714.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7165511 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/274714 | vdb entry vendor advisory |