Use of a broken or risky cryptographic algorithm in IBM WebSphere Application Server Liberty - CVE-2022-22310

 

Use of a broken or risky cryptographic algorithm in IBM WebSphere Application Server Liberty - CVE-2022-22310

Published: March 24, 2022


Vulnerability identifier: #VU61581
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-22310
CWE-ID: CWE-327
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Affected software:
IBM WebSphere Application Server Liberty
IBM Cloud Transformation Advisor
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Transformation Extender Advanced
IBM Common Licensing
IBM Copy Services Manager

Detailed vulnerability description

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to usage of a weak cryptographic algorithms. A remote attacker can intercept and decrypt traffic.


How to mitigate CVE-2022-22310

Install updates from vendor's website.

Sources