Use of a broken or risky cryptographic algorithm in IBM WebSphere Application Server Liberty - CVE-2022-22310
Published: March 24, 2022
Vulnerability identifier: #VU61581
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-22310
CWE-ID: CWE-327
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Affected software:
IBM WebSphere Application Server Liberty
IBM Cloud Transformation Advisor
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Transformation Extender Advanced
IBM Common Licensing
IBM Copy Services Manager
IBM WebSphere Application Server Liberty
IBM Cloud Transformation Advisor
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Transformation Extender Advanced
IBM Common Licensing
IBM Copy Services Manager
Detailed vulnerability description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to usage of a weak cryptographic algorithms. A remote attacker can intercept and decrypt traffic.
How to mitigate CVE-2022-22310
Install updates from vendor's website.