IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7158031 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/294721 | vdb entry |