IBM Support

PH12533: Client-side HTTP parameter pollution vulnerability in WebSphere Application Server Admin Console (CVE-2019-4271)

Download


Downloadable File

File link File size File description

Abstract

Client-side HTTP parameter pollution vulnerability in WebSphere Application Server Admin Console (CVE-2019-4271)

Download Description

PH12533 resolves the following problem:

ERROR DESCRIPTION:
Client-side HTTP parameter pollution vulnerability in WebSphere Application Server Admin Console (CVE-2019-4271)

LOCAL FIX:

PROBLEM SUMMARY:
Client-side HTTP parameter pollution vulnerability in WebSphere Application Server Admin Console (CVE-2019-4271)

PROBLEM CONCLUSION:
Admin console vulnerabilities were removed.
The fix for this APAR is currently targeted for inclusion in the fix pack 8.5.5.16 and 9.0.5.0.
Please refer to the Recommended Updates page for delivery information:
http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980

Prerequisites

None

Installation Instructions

Please review the readme.txt for detailed installation instructions.

URL SIZE(Bytes)
V85 Readme 2530
V90 Readme 2410

Download Package

DOWNLOAD RELEASE DATE SIZE(Bytes)

DOWNLOAD Options

What is Fix Central(FC)?

8.5.5.0-WS-WASND-IFPH12533 08-29-2019 1235173 FC
9.0.0.0-WS-WASND-IFPH12533 08-29-2019 1250918 FC

Problems Solved

PH12533

On

Technical Support

Contact IBM Support using SR (http://www.ibm.com/software/support/probsub.html), visit the support web site, or contact 1-800-IBM-SERV (U.S. only).

Document Location

Worldwide

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Component":"General","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF012","label":"IBM i"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"8.5.5;8.5.5.1;8.5.5.10;8.5.5.11;8.5.5.12;8.5.5.13;8.5.5.14;8.5.5.15;8.5.5.2;8.5.5.3;8.5.5.4;8.5.5.5;8.5.5.6;8.5.5.7;8.5.5.8;8.5.5.9;9.0.0.0;9.0.0.1;9.0.0.10;9.0.0.11;9.0.0.2;9.0.0.3;9.0.0.4;9.0.0.5;9.0.0.6;9.0.0.7;9.0.0.8;9.0.0.9","Edition":"Network Deployment","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
03 September 2019

UID

ibm11072436