IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/97713http://www-01.ibm.com/support/docview.wss?uid=swg21690185http://www-01.ibm.com/support/docview.wss?uid=swg1PI23430