Improper Authentication in Apache Shiro - CVE-2022-40664

 

Improper Authentication in Apache Shiro - CVE-2022-40664

Published: October 12, 2022 / Updated: October 16, 2022


Vulnerability identifier: #VU68270
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40664
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when forwarding or including requests via RequestDispatcher. A remote attacker can bypass authentication process and gain unauthorized access to the application.


Affected software

Apache Shiro
WebSphere Service Registry and Repository
IBM Sterling Partner Engagement Manager
Oracle WebCenter Sites
PowerStore T
IBM Cognos Analytics

How to mitigate CVE-2022-40664

Install updates from vendor's website.

Apache Shiro - update to 1.10.0
PowerStore T - update to 3.5.0.1-2083289
IBM Cognos Analytics - addressed in versions 11.1.7.6, 11.2.4.1 IF1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins