Improper Authentication in Apache Shiro - CVE-2022-32532
Published: June 29, 2022 / Updated: August 16, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in RegexRequestMatcher configuration. A remote attacker can bypass authentication process and gain unauthorized access to the application. Applications using RegExPatternMatcher with `.` in the regular expression are affected by the vulnerability.
Affected software
IBM Sterling Partner Engagement Manager
IBM Engineering Requirements Management DOORS Next
PowerStore T
Oracle WebCenter Sites
How to mitigate CVE-2022-32532
IBM Sterling Partner Engagement Manager - addressed in versions 6.1.2.6, 6.2.0.4, 6.2.1.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
PowerStore T - update to 3.5.0.1-2083289