Spoofing attack in IBM WebSphere Application Server - CVE-2022-38712
Published: October 18, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of JAX-WS Web Services requests. A remote attacker can perform SOAPAction spoofing.
Affected software
IBM Tivoli Business Service Manager
IBM Tivoli Netcool/OMNIbus WebGUI
Jazz for Service Management
IBM Tivoli System Automation Application Manager
IBM Integration Bus
InfoSphere Master Data Management
Content Collector for Email
IBM Security Verify Governance
IBM App Connect Enterprise
How to mitigate CVE-2022-38712
Install updates from vendor's website.
For V9.0.0.0 through 9.0.5.13:
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PH49111
--OR--
· Apply Fix Pack 9.0.5.14 or later (targeted availability 4Q2022).
For V8.5.0.0 through 8.5.5.22:
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PH49111
--OR--
· Apply Fix Pack 8.5.5.23 or later (targeted availability 1Q2023).
For V8.0.0.0 through 8.0.0.15:
· Upgrade to 8.0.0.15 and then apply Interim Fix PH49111
· Upgrade to 7.0.0.45 and then apply Interim Fix PH49111
IBM Security Verify Governance - update to 10.0.1.0.3
External References
Related Security Bulletins
- Spoofing attack in IBM WebSphere Application Server
- Spoofing attack in IBM Master Data Management
- Spoofing attack in IBM Content Collector for Email
- Spoofing attack in IBM Tivoli Business Service Manager
- Spoofing attack in IBM Tivoli Netcool/OMNIbus WebGUI
- Spoofing attack in IBM Tivoli System Automation Application Manager
- SOAPAction spoofing in Jazz for Service Management (JazzSM)
- Spoofing attack in IBM App Connect Enterprise and IBM Integration Bus
- Spoofing attack in IBM Security Verify Governance