Improper Authentication in IBM WebSphere Application Server Liberty - CVE-2022-22475

 

Improper Authentication in IBM WebSphere Application Server Liberty - CVE-2022-22475

Published: June 13, 2022


Vulnerability identifier: #VU64197
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22475
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges within the application.

The vulnerability exists due to an unspecified error. A remote authenticated user can spoof identity of other application users.


Affected software

IBM WebSphere Application Server Liberty
Voice Gateway
IBM MQ Operator
Log Analysis
IBM SPSS Analytic Server
IBM Spectrum Control
IBM SPSS Collaboration and Deployment Services
IBM Maximo Application Suite
CICS Transaction Gateway
IBM Security Verify Governance
IBM Cloud Pak for Business Automation
IBM Cloud Application Business Insights
IBM Operations Analytics Predictive Insights
IBM Cloud Transformation Advisor
IBM Match 360
IBM Elastic Storage System
IBM Cloud Application Performance Management (APM)
IBM Common Licensing
IBM MQ
Rational Asset Analyzer
IBM supplied MQ Advanced container images
B2B Advanced Communications
Multi-Enterprise Integration Gateway
InfoSphere Global Name Management
IBM Security Verify Access
IBM Watson Explorer Foundational Components
IBM Watson Explorer Analytical Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
IBM Watson Explorer Deep Analytics Edition oneWEX
IBM Watson Explorer Deep Analytics Edition Analytical Components
IBM CICS TX Standard
IBM CICS TX Advanced
Liberty for Java for IBM Cloud
IBM Spectrum Scale
IBM Cognos Controller

How to mitigate CVE-2022-22475

Install updates from vendor's website.

IBM WebSphere Application Server Liberty - update to 22.0.0.6
Voice Gateway - update to 1.0.8.1
IBM MQ Operator - addressed in versions 1.3.6, 2.0.1
IBM Spectrum Control - update to 5.4.8
IBM Maximo Application Suite - update to 8.8.2
IBM supplied MQ Advanced container images - addressed in versions 9.2.0.6-r1, 9.3.0.0-r2
IBM Security Verify Access - update to 10.0.5.0
IBM Security Verify Governance - update to 10.0.4
IBM Watson Explorer Foundational Components - update to 11.0.2.14
IBM Watson Explorer Analytical Components - update to 11.0.2.14
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition oneWEX - update to 12.0.3.10
IBM Watson Explorer Deep Analytics Edition Analytical Components - update to 12.0.3.10
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
B2B Advanced Communications - update to 1.0.0.8
Multi-Enterprise Integration Gateway - update to 1.0.0.8
IBM Cloud Application Business Insights - update to 1.1.7.5
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
IBM Cloud Transformation Advisor - update to 3.2.2
Liberty for Java for IBM Cloud - update to 3.70-20220525-0737
IBM Match 360 - update to 4.5.1
IBM Spectrum Scale - addressed in versions 5.1.2.6, 5.1.4.1
InfoSphere Global Name Management - update to 6.0.0.14
IBM Elastic Storage System - addressed in versions 6.1.2.4, 6.1.4.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Common Licensing - update to 9.0.0.1
IBM MQ - addressed in versions 9.1.0.12, 9.2.0.6, 9.3
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix10, 11.1.0.0 ifix3
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2

External References

Related Security Bulletins