Information disclosure in IBM WebSphere Application Server Liberty - CVE-2022-22393

 

Information disclosure in IBM WebSphere Application Server Liberty - CVE-2022-22393

Published: August 1, 2022


Vulnerability identifier: #VU65906
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22393
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote user can issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server.


Affected software

IBM WebSphere Application Server Liberty
IBM MQ Operator
IBM SPSS Collaboration and Deployment Services
IBM Operations Analytics Predictive Insights
IBM Cloud Transformation Advisor
IBM Match 360
IBM Tivoli Netcool Impact
IBM Maximo Application Suite
PowerVM NovaLink
Rational Asset Analyzer
IBM supplied MQ Advanced container images
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2022-22393

Install updates from vendor's website.

IBM WebSphere Application Server Liberty - update to 22.0.0.6
IBM MQ Operator - addressed in versions 1.3.6, 2.0.1
IBM supplied MQ Advanced container images - addressed in versions 9.2.0.6-r1, 9.3.0.0-r2
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
IBM Cloud Transformation Advisor - update to 3.2.2
IBM Match 360 - update to 4.5.1
IBM Tivoli Netcool Impact - update to 7.1.0.26
IBM Maximo Application Suite - addressed in versions 8.6.5, 8.7.3, 8.8.1, 8.9.0
IBM CICS TX Standard - update to 11.1.0.0 ifix3

External References

Related Security Bulletins