IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a failure to honor security configuration.
The server contains a protection mechanism that assumes that any URI that is accessed using HTTP GET will not cause a state change to the associated resource. This might allow attackers to bypass intended access restrictions and conduct resource modification and deletion attacks, since some applications allow GET to modify state.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Websphere_application_server | Ibm | 17.0.0.3 (including) | 25.0.0.7 (including) | 
| Websphere_application_server | Ibm | 9.0.0.0 (including) | 9.0.0.0 (including) |