IBM WebSphere eXtreme Scale 8.6.2.0 < 8.6.2.2 (7282872)

high Nessus Plugin ID 333386

Synopsis

The remote web application server is affected by multiple vulnerabilities

Description

The version of IBM WebSphere eXtreme Scale installed on the remote host is prior to 8.6.2.2 IBM. It is, therefore, affected by multiple vulnerabilities as referenced in the 7282872 advisory.

- Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
(CVE-2021-23337)

- Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names.
Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names. (CVE-2026-4800)

- Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and
_.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA- xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype. The issue permits deletion of prototype properties but does not allow overwriting their original behavior. Patches: This issue is patched in 4.18.0. Workarounds: None. Upgrade to the patched version. (CVE-2026-2950)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Please see vendor advisory for details.

See Also

https://www.ibm.com/support/pages/node/7282872

Plugin Details

Severity: High

ID: 333386

File Name: ibm_websphere_xs_7282872.nasl

Version: 1.1

Type: Local

Agent: unix

Family: Web Servers

Published: 8/8/2026

Updated: 8/8/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.06

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2021-23337

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-4800

CVSS v4

Risk Factor: High

Base Score: 7.9

Threat Score: 6.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H

CVSS Score Source: CVE-2025-13465

Vulnerability Information

CPE: cpe:/a:ibm:websphere_extreme_scale

Required KB Items: installed_sw/IBM WebSphere eXtreme Scale, Settings/ParanoidReport

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/7/2026

Vulnerability Publication Date: 2/15/2021

Reference Information

CVE: CVE-2021-23337, CVE-2025-13465, CVE-2026-2950, CVE-2026-33937, CVE-2026-33939, CVE-2026-4800, CVE-2026-9002