Description
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
References
www.ibm.com/support/pages/node/7274072