VYPR
Unrated severityNVD Advisory· Published Mar 1, 2024· Updated Apr 22, 2025

IBM WebSphere Application Server Liberty information disclosure

CVE-2023-50312

Description

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. IBM X-Force ID: 274711.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM WebSphere Liberty fails to honor user TLS configuration for outbound connections, potentially allowing weaker security than expected.

Vulnerability

IBM WebSphere Application Server Liberty versions 17.0.0.3 through 24.0.0.2 do not properly honor user configuration for outbound TLS connections [1]. This causes the server to negotiate TLS connections with weaker security than what the administrator intended, potentially allowing the use of deprecated protocols or cipher suites.

Exploitation

An attacker with adjacent network access (CVSS:AV:A) and prior knowledge of the outbound connection timing can exploit this vulnerability. The complexity is high (CVSS:AC:H) as the attacker must position themselves to intercept or modify the TLS handshake. No authentication or user interaction is required. The failure to enforce the configured TLS settings allows the attacker to potentially downgrade the security of the connection [1].

Impact

Successful exploitation of this vulnerability results in a high confidentiality impact (CVSS:C:H). An attacker may obtain sensitive information transmitted over the vulnerable outbound TLS connection, as the weakened security could expose the data in transit. Integrity and availability are not affected [1].

Mitigation

IBM recommends upgrading to Liberty Fix Pack 24.0.0.3 or later, which contains the fix for APAR PH58870. Alternatively, apply Interim Fix PH60113 to the current installation. No workarounds are available [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.