CVE Vulnerabilities

CVE-2024-56339

Trusting HTTP Permission Methods on the Server Side

Published: Aug 07, 2025 | Modified: Aug 14, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.

Weakness

The server contains a protection mechanism that assumes that any URI that is accessed using HTTP GET will not cause a state change to the associated resource. This might allow attackers to bypass intended access restrictions and conduct resource modification and deletion attacks, since some applications allow GET to modify state.

Affected Software

Name Vendor Start Version End Version
Websphere_application_server Ibm 17.0.0.3 (including) 25.0.0.7 (including)
Websphere_application_server Ibm 9.0.0.0 (including) 9.0.0.0 (including)

Potential Mitigations

References