Improper validation of certificate with host mismatch in IBM WebSphere Application Server - CVE-2022-39161
Published: May 3, 2023
Vulnerability details
The vulnerability allows a remote user to perform MitM attack.
The vulnerability exists due to improper certificate validation issued by a trusted CA when configured to communicate with the Web Server Plug-ins for IBM WebSphere Application Server. A remote user can perform a man-in-the-middle (MitM) attack and gain access to sensitive information.
Affected software
IBM WebSphere Application Server Liberty
IBM Operations Analytics Predictive Insights
Engineering Workflow Management
IBM Spectrum Control
IBM Tivoli Monitoring
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Jazz Foundation
Engineering Test Management
IBM i
IBM Cloud Pak System
How to mitigate CVE-2022-39161
IBM Spectrum Control - update to 5.4.10.2
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Security Verify Governance - update to 10.0.1.0.5
External References
Related Security Bulletins
- MitM attack in IBM WebSphere Application Server
- MitM attack in IBM WebSphere Application Server Liberty Web Server Plug-ins
- Multiple vulnerabilities in IBM Security Verify Governance
- Improper validation of certificate with host mismatch in The IBM Engineering Lifecycle Engineering
- IBM Operations Analytics Predictive Insights update for IBM WebSphere Application Server
- Multiple vulnerabilities in IBM Tivoli Monitoring
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM Spectrum Control
- Improper validation of certificate with host mismatch in IBM i
- Improper validation of certificate with host mismatch in IBM Cloud Pak System