Описание
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
A flaw was found in the ORB (Object Request Broker) component of IBM SDK, Java Technology Edition. A malicious IIOP (Internet Inter-ORB Protocol) server could exploit this vulnerability to force the loading and creation of unauthorized software components. This could lead to the execution of arbitrary code, potentially compromising the affected system.
Меры по смягчению последствий
To mitigate this issue, ensure that applications are configured to only connect to trusted IIOP servers. Restrict network access to prevent connections to untrusted or external IIOP endpoints.
Дополнительная информация
Статус:
8.1 High
CVSS3
Связанные уязвимости
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
8.1 High
CVSS3