CVE-2017-1504: IBM WebSphere Application Server

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES password encryption. IBM X-Force ID: 129579.

Affected products

  • IBM WebSphere Application Server: version 9.0.0.4 only

Published 2017-08-03. Last modified 2026-06-17.