Improper Authentication in IBM WebSphere Application Server Liberty - CVE-2022-22475
Published: June 13, 2022
Vulnerability identifier: #VU64197
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22475
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to an unspecified error. A remote authenticated user can spoof identity of other application users.
Affected software
IBM WebSphere Application Server Liberty
Voice Gateway
IBM MQ Operator
Log Analysis
IBM SPSS Analytic Server
IBM Spectrum Control
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite
CICS Transaction Gateway
IBM Security Verify Governance
IBM Cloud Pak for Business Automation
IBM Cloud Application Business Insights
IBM Operations Analytics Predictive Insights
IBM Cloud Transformation Advisor
IBM Match 360
IBM Elastic Storage System
IBM Cloud Application Performance Management (APM)
IBM Common Licensing
IBM MQ
Rational Asset Analyzer
IBM supplied MQ Advanced container images
B2B Advanced Communications
Multi-Enterprise Integration Gateway
InfoSphere Global Name Management
IBM Security Verify Access
IBM Watson Explorer Foundational Components
IBM Watson Explorer Analytical Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
IBM Watson Explorer Deep Analytics Edition oneWEX
IBM Watson Explorer Deep Analytics Edition Analytical Components
IBM CICS TX Standard
IBM CICS TX Advanced
Liberty for Java for IBM Cloud
IBM Spectrum Scale
IBM Cognos Controller
Voice Gateway
IBM MQ Operator
Log Analysis
IBM SPSS Analytic Server
IBM Spectrum Control
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite
CICS Transaction Gateway
IBM Security Verify Governance
IBM Cloud Pak for Business Automation
IBM Cloud Application Business Insights
IBM Operations Analytics Predictive Insights
IBM Cloud Transformation Advisor
IBM Match 360
IBM Elastic Storage System
IBM Cloud Application Performance Management (APM)
IBM Common Licensing
IBM MQ
Rational Asset Analyzer
IBM supplied MQ Advanced container images
B2B Advanced Communications
Multi-Enterprise Integration Gateway
InfoSphere Global Name Management
IBM Security Verify Access
IBM Watson Explorer Foundational Components
IBM Watson Explorer Analytical Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
IBM Watson Explorer Deep Analytics Edition oneWEX
IBM Watson Explorer Deep Analytics Edition Analytical Components
IBM CICS TX Standard
IBM CICS TX Advanced
Liberty for Java for IBM Cloud
IBM Spectrum Scale
IBM Cognos Controller
How to mitigate CVE-2022-22475
Install updates from vendor's website.
IBM WebSphere Application Server Liberty - update to 22.0.0.6
Voice Gateway - update to 1.0.8.1
IBM MQ Operator - addressed in versions 1.3.6, 2.0.1
IBM Spectrum Control - update to 5.4.8
IBM Maximo Application Suite - update to 8.8.2
IBM supplied MQ Advanced container images - addressed in versions 9.2.0.6-r1, 9.3.0.0-r2
IBM Security Verify Access - update to 10.0.5.0
IBM Security Verify Governance - update to 10.0.4
IBM Watson Explorer Foundational Components - update to 11.0.2.14
IBM Watson Explorer Analytical Components - update to 11.0.2.14
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition oneWEX - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.10
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
B2B Advanced Communications - update to 1.0.0.8
Multi-Enterprise Integration Gateway - update to 1.0.0.8
IBM Cloud Application Business Insights - update to 1.1.7.5
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
IBM Cloud Transformation Advisor - update to 3.2.2
Liberty for Java for IBM Cloud - update to 3.70-20220525-0737
IBM Match 360 - update to 4.5.1
IBM Spectrum Scale - addressed in versions 5.1.2.6, 5.1.4.1
InfoSphere Global Name Management - update to 6.0.0.14
IBM Elastic Storage System - addressed in versions 6.1.2.4, 6.1.4.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Common Licensing - update to 9.0.0.1
IBM MQ - addressed in versions 9.1.0.12, 9.2.0.6, 9.3
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix10, 11.1.0.0 ifix3
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
Voice Gateway - update to 1.0.8.1
IBM MQ Operator - addressed in versions 1.3.6, 2.0.1
IBM Spectrum Control - update to 5.4.8
IBM Maximo Application Suite - update to 8.8.2
IBM supplied MQ Advanced container images - addressed in versions 9.2.0.6-r1, 9.3.0.0-r2
IBM Security Verify Access - update to 10.0.5.0
IBM Security Verify Governance - update to 10.0.4
IBM Watson Explorer Foundational Components - update to 11.0.2.14
IBM Watson Explorer Analytical Components - update to 11.0.2.14
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition oneWEX - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.10
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
B2B Advanced Communications - update to 1.0.0.8
Multi-Enterprise Integration Gateway - update to 1.0.0.8
IBM Cloud Application Business Insights - update to 1.1.7.5
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
IBM Cloud Transformation Advisor - update to 3.2.2
Liberty for Java for IBM Cloud - update to 3.70-20220525-0737
IBM Match 360 - update to 4.5.1
IBM Spectrum Scale - addressed in versions 5.1.2.6, 5.1.4.1
InfoSphere Global Name Management - update to 6.0.0.14
IBM Elastic Storage System - addressed in versions 6.1.2.4, 6.1.4.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Common Licensing - update to 9.0.0.1
IBM MQ - addressed in versions 9.1.0.12, 9.2.0.6, 9.3
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix10, 11.1.0.0 ifix3
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
External References
Related Security Bulletins
- Identity spoofing in IBM WebSphere Application Server Liberty
- Identity spoofing in Liberty for Java for IBM Cloud
- Multiple vulnerabilities in IBM Watson Explorer
- Improper Authentication in IBM Voice Gateway
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Identity spoofing in IBM Match 360
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Spectrum Control
- Identity spoofing in CICS Transaction Gateway
- Identity Spoofing in IBM Operations Analytics
- Multiple vulnerabilities in SPSS Collaboration and Deployment Services
- Identity spoofing in Rational Asset Analyzer
- Identity spoofing in IBM Spectrum Scale
- Identity spoofing in IBM Elastic Storage System
- Identity spoofing in IBM SPSS Analytic Server
- Identity spoofing in IBM CICS TX Standard
- Identity spoofing in IBM MQ
- Multiple vulnerabilities in IBM Operations Analytics Predictive Insights
- Multiple vulnerabilities in IBM Cloud Application Business Insights
- Multiple vulnerabilities in IBM InfoSphere Global Name Management
- Multiple vulnerabilities in IBM Security Verify Access
- Improper authentication in IBM B2B Advanced Communications
- Improper Authentication in IBM Maximo Application Suite - Monitor Component
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Cognos Controller
- Multiple vulnerabilities in IBM Application Performance Management
- Improper authentication in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Common Licensing