Privilege Escalation via Swagger Document in IBM WebSphere Application Server

Privilege Escalation via Swagger Document in IBM WebSphere Application Server

CVE-2016-2945 · MEDIUM Severity

AV:N/AC:M/AU:S/C:P/I:P/A:P

The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote authenticated users to gain privileges via an external reference in a Swagger document.

Learn more about our Cis Benchmark Audit For Ibm I.