Spoofing attack in IBM WebSphere Application Server - CVE-2022-38712

 

Spoofing attack in IBM WebSphere Application Server - CVE-2022-38712

Published: October 18, 2022


Vulnerability identifier: #VU68375
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38712
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect processing of JAX-WS Web Services requests. A remote attacker can perform SOAPAction spoofing.


Affected software

IBM WebSphere Application Server
IBM Tivoli Business Service Manager
IBM Tivoli Netcool/OMNIbus WebGUI
Jazz for Service Management
IBM Tivoli System Automation Application Manager
IBM Integration Bus
InfoSphere Master Data Management
Content Collector for Email
IBM Security Verify Governance
IBM App Connect Enterprise

How to mitigate CVE-2022-38712

Install updates from vendor's website.

For V9.0.0.0 through 9.0.5.13:
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix  PH49111
--OR--
· Apply Fix Pack 9.0.5.14 or later (targeted availability 4Q2022). 

For V8.5.0.0 through 8.5.5.22:
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PH49111
--OR--
· Apply Fix Pack 8.5.5.23 or later (targeted availability 1Q2023). 

For V8.0.0.0 through 8.0.0.15:
· Upgrade to 8.0.0.15 and then apply Interim Fix PH49111

For V7.0.0.0 through 7.0.0.45:
· Upgrade to 7.0.0.45 and  then apply Interim Fix PH49111


Content Collector for Email - update to 4.0.1.9 IF014
IBM Security Verify Governance - update to 10.0.1.0.3

External References

Related Security Bulletins