Use of a broken or risky cryptographic algorithm in IBM WebSphere Application Server Liberty - CVE-2022-22310

 

Use of a broken or risky cryptographic algorithm in IBM WebSphere Application Server Liberty - CVE-2022-22310

Published: March 24, 2022


Vulnerability identifier: #VU61581
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22310
CWE-ID: CWE-327
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to usage of a weak cryptographic algorithms. A remote attacker can intercept and decrypt traffic.


Affected software

IBM WebSphere Application Server Liberty
IBM Cloud Transformation Advisor
IBM IoT MessageSight
IBM WIoTP MessageGateway
IBM Transformation Extender Advanced
IBM Common Licensing
IBM Copy Services Manager

How to mitigate CVE-2022-22310

Install updates from vendor's website.

IBM Cloud Transformation Advisor - update to 3.1.0
IBM WIoTP MessageGateway - update to 5.0.0.2
IBM Transformation Extender Advanced - addressed in versions 9.0.2.6, 10.0.1.7
IBM Copy Services Manager - update to 6.3.2
IBM Common Licensing - update to 9.0.0.1

External References

Related Security Bulletins