CVE-2019-4304: IBM WebSphere Application Server

Medium severity, CVSS 6.3. EPSS: 1% chance of exploitation in the next 30 days.

IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by improper session validation. IBM X-Force ID: 160950.

Affected products

  • IBM WebSphere Application Server: before 19.0.0.10 (fixed in 19.0.0.10)

Published 2019-09-30. Last modified 2026-06-17.