Vulnerability Bulletins |
IBM Security Bulletin: Bypass security restrictions in WebSphere Application Server (CVE-2016-0385) |
|
| Affected software | IBM |
|
There is a potential bypass security restriction vulnerability in IBM WebSphere Application Server. This will only occur in environments that have the webcontainer custom property HttpSessionIdReuse enabled.CVE(s): CVE-2016-0385Affected product(s) and affected version(s):This vulnerability affects the following versions and releases of IBM WebSphere Application Server Liberty Version 9.0 Version 8.5.5 Version 8.5 Version 8.0 Version 7.0Refer to the following reference URLs for remediation and More info: https://www.ibm.com/blogs/psirt/ibm-security-bulletin-bypass-security-restrictions-in-websphere-application-server-cve-2016-0385/ |
|






