vulnerability

IBM WebSphere Application Server: CVE-2017-3736: WebSphere Application Server Vulnerability

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Nov 2, 2017
Added
Jul 20, 2018
Modified
Aug 11, 2025

Description

OpenSSL could allow a remote attacker to obtain sensitive information, caused by a carry propagation flaw in the x86_64 Montgomery squaring function bn_sqrx8x_internal(). An attacker with online access to an unpatched system could exploit this vulnerability to obtain information about the private key.

Solutions

ibm-was-install-7-0-0-0-pi91913ibm-was-install-8-0-0-0-pi94222ibm-was-install-8-5-0-0-pi4222ibm-was-install-9-0-0-0-pi4222ibm-was-upgrade-7-0-0-0-7-0-0-45ibm-was-upgrade-8-0-0-0-8-0-0-15ibm-was-upgrade-8-5-0-0-8-5-5-14ibm-was-upgrade-9-0-0-0-9-0-0-8
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.