#VU75686 Improper validation of certificate with host mismatch in IBM WebSphere Application Server - CVE-2022-39161
Published: May 3, 2023
IBM WebSphere Application Server
IBM Corporation
Description
The vulnerability allows a remote user to perform MitM attack.
The vulnerability exists due to improper certificate validation issued by a trusted CA when configured to communicate with the Web Server Plug-ins for IBM WebSphere Application Server. A remote user can perform a man-in-the-middle (MitM) attack and gain access to sensitive information.