IBM Support

PH29368:Denial of service attack vulnerability in oauth-2.0 or openidConnectServer-1.0 (CVE-2020-4590 CVSS score 5.3)

Download


Downloadable File

File link File size File description

Abstract

Denial of service attack vulnerability in oauth-2.0 or openidConnectServer-1.0 (CVE-2020-4590 CVSS score 5.3)

Download Description

PH29368 resolves the following problem:

ERROR DESCRIPTION:
WebSphere Liberty running oauth-2.0 or openidConnectServer-1.0 features is vulnerable to a denial of service attack (CVE-2020-4590. CVSS score 5.3).

LOCAL FIX:

PROBLEM SUMMARY:
WebSphere Liberty running oauth-2.0 or openidConnectServer-1.0 features is vulnerable to a denial of service attack (CVE-2020-4590. CVSS score 5.3).

This fix supersedes (includes) the fix for PH22080, PH24154

Prerequisites

None

Installation Instructions

Review the readme.txt for detailed installation instructions.

URL SIZE(Bytes)
20.0.0.6 Archive Readme 2546
20.0.0.9 Readme 2297
20.0.0.3 Archive Readme 2782
20.0.0.9 Archive Readme 2546

Download Package

DOWNLOAD RELEASE DATE SIZE(Bytes)

DOWNLOAD Options

What is Fix Central(FC)?

20006-wlp-archive-IFPH29368 16 September 2020 2924610 FC
20.0.0.3-WS-WLP-IFPH29368 16 September 2020 3548623 FC
20.0.0.6-WS-WLP-IFPH29368 16 September 2020 2998235 FC
20.0.0.9-WS-WLP-IFPH29368 16 September 2020 3015472 FC
20003-wlp-archive-IFPH29368 16 September 2020 3474259 FC
20009-wlp-archive-IFPH29368 16 September 2020 2941825 FC

Problems Solved

PH29368, PH22080, PH24154

On

Technical Support

Contact IBM Support at https://www.ibm.com/software/mysupport/s/ or 1-800-IBM-SERV (US only).

Document Location

Worldwide

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Component":"General","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF012","label":"IBM i"},{"code":"PF016","label":"Linux"},{"code":"PF017","label":"Mac OS"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"20.0.0.3;20.0.0.6;20.0.0.9","Edition":"Base","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
16 September 2020

UID

ibm16333599