Improper validation of certificate with host mismatch in IBM WebSphere Application Server - CVE-2022-39161

 

Improper validation of certificate with host mismatch in IBM WebSphere Application Server - CVE-2022-39161

Published: May 3, 2023


Vulnerability identifier: #VU75686
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-39161
CWE-ID: CWE-297
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform MitM attack.

The vulnerability exists due to improper certificate validation issued by a trusted CA when configured to communicate with the Web Server Plug-ins for IBM WebSphere Application Server. A remote user can perform a man-in-the-middle (MitM) attack and gain access to sensitive information.


Affected software

IBM WebSphere Application Server
IBM WebSphere Application Server Liberty
IBM Operations Analytics Predictive Insights
Engineering Workflow Management
IBM Spectrum Control
IBM Tivoli Monitoring
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Jazz Foundation
Engineering Test Management
IBM i
IBM Cloud Pak System

How to mitigate CVE-2022-39161

Install updates from vendor's website.

IBM Cloud Pak System - update to 2.3.3.7 iFix 01
IBM Spectrum Control - update to 5.4.10.2
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
IBM Security Verify Governance - update to 10.0.1.0.5

External References

Related Security Bulletins