Improper Authentication in Apache Shiro - CVE-2022-40664
Published: October 12, 2022 / Updated: October 16, 2022
Vulnerability identifier: #VU68270
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40664
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when forwarding or including requests via RequestDispatcher. A remote attacker can bypass authentication process and gain unauthorized access to the application.
Affected software
Apache Shiro
WebSphere Service Registry and Repository
IBM Sterling Partner Engagement Manager
Oracle WebCenter Sites
PowerStore T
IBM Cognos Analytics
WebSphere Service Registry and Repository
IBM Sterling Partner Engagement Manager
Oracle WebCenter Sites
PowerStore T
IBM Cognos Analytics
How to mitigate CVE-2022-40664
Install updates from vendor's website.
Apache Shiro - update to 1.10.0
PowerStore T - update to 3.5.0.1-2083289
IBM Cognos Analytics - addressed in versions 11.1.7.6, 11.2.4.1 IF1
PowerStore T - update to 3.5.0.1-2083289
IBM Cognos Analytics - addressed in versions 11.1.7.6, 11.2.4.1 IF1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Authentication bypass in Apache Shiro
- Improper authentication in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in Oracle WebCenter Sites
- Multiple vulnerabilities in IBM WebSphere Service Registry and Repository
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in Dell PowerStore Family