Authentication Bypass by Spoofing in IBM WebSphere Application Server Liberty - CVE-2022-22476

 

Authentication Bypass by Spoofing in IBM WebSphere Application Server Liberty - CVE-2022-22476

Published: July 28, 2022


Vulnerability identifier: #VU65845
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22476
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute identity spoofing attacks.

The vulnerability exists due to an unspecified error in IBM WebSphere Application Server Liberty. A remote authenticated user can send a specially crafted request to perform identity spoofing attacks.


Affected software

IBM WebSphere Application Server Liberty
Log Analysis
IBM Spectrum Control
IBM Tivoli Netcool Impact
IBM SPSS Collaboration and Deployment Services
CICS Transaction Gateway
IBM Security Verify Governance
IBM Cloud Application Business Insights
IBM Operations Analytics Predictive Insights
Netcool Operations Insight
IBM MQ Operator
Financial Transaction Manager for Corporate Payment Services (CPS)
Financial Transaction Manager for Digital Payments (DP)
IBM Spectrum Scale for IBM Elastic Storage Server
IBM Elastic Storage System
IBM Spectrum Protect Operations Center
Maximo Manage Application in IBM Maximo Application Suite
IBM MQ
IBM Robotic Process Automation
PowerVM NovaLink
IBM Engineering Requirements Management DOORS Next
IBM Virtualization Engine TS7700 3948-VED
B2B Advanced Communications
Multi-Enterprise Integration Gateway
Financial Transaction Manager for High Value Payments
InfoSphere Global Name Management
IBM Security Directory Server
IBM Security Directory Suite
IBM Spectrum Protect Client Management Service
IBM MQ Appliance
IBM supplied MQ Advanced container images
Liberty for Java for IBM Cloud
Engineering Lifecycle Management
IBM CICS TX Advanced
IBM CICS TX Standard
Virtualization Engine TS7700 3957-VEC
Virtualization Engine TS7700 3957-VED
IBM Security Verify Access
IBM Spectrum Scale
IBM Copy Services Manager

How to mitigate CVE-2022-22476

Install updates from vendor's website.

IBM WebSphere Application Server Liberty - update to 22.0.0.8
Liberty for Java for IBM Cloud - update to 3.72-20220720-1509
IBM Spectrum Control - update to 5.4.9
IBM Tivoli Netcool Impact - update to 7.1.0.27
Virtualization Engine TS7700 3957-VEC - addressed in versions 8.51.2.12 VTD_EXEC.900, 8.52.102.13 VTD_EXEC.901, 8.52.200.111 VTD_EXEC.902, 8.53.0.63 VTD_EXEC.903
Virtualization Engine TS7700 3957-VED - addressed in versions 8.51.2.12 VTD_EXEC.900, 8.52.102.13 VTD_EXEC.901, 8.52.200.111 VTD_EXEC.902, 8.53.0.63 VTD_EXEC.903
IBM Virtualization Engine TS7700 3948-VED - update to 8.53.0.63 VTD_EXEC.903
IBM Security Verify Access - update to 10.0.5.0
IBM Security Verify Governance - update to 10.0.4
B2B Advanced Communications - update to 1.0.0.8
Multi-Enterprise Integration Gateway - update to 1.0.0.8
IBM Cloud Application Business Insights - update to 1.1.7.5
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
Netcool Operations Insight - update to 1.6.7
IBM MQ Operator - addressed in versions 2.0.4, 2.1.0
Financial Transaction Manager for Corporate Payment Services (CPS) - update to 3.2.11
Financial Transaction Manager for Digital Payments (DP) - update to 3.2.11
Financial Transaction Manager for High Value Payments - update to 3.2.11
IBM Spectrum Scale - addressed in versions 5.1.2.7, 5.1.6.0
InfoSphere Global Name Management - update to 6.0.0.14
IBM Spectrum Scale for IBM Elastic Storage Server - addressed in versions 6.1.2.5, 6.1.5.0
IBM Elastic Storage System - addressed in versions 6.1.2.5, 6.1.5.0
IBM Copy Services Manager - update to 6.3.5
IBM Security Directory Server - update to 6.4.0.27
IBM Security Directory Suite - update to 8.0.1.19
IBM Spectrum Protect Operations Center - update to 8.1.16
IBM Spectrum Protect Client Management Service - update to 8.1.16
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.5.6, 8.6.2
IBM MQ - addressed in versions 9.1.0.12, 9.3.0.1, 9.3.1
IBM MQ Appliance - addressed in versions 9.2.0.6, 9.2.5.2, 9.3.0.1
IBM supplied MQ Advanced container images - update to 9.3.1.0
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix10, 11.1.0.0 ifix3
IBM CICS TX Standard - update to 11.1.0.0 ifix3
IBM Robotic Process Automation - update to 21.0.4

External References

Related Security Bulletins