PT-2022-15392 · Ibm · Ibm Websphere Application Server
Published
2022-05-20
·
Updated
2022-06-02
·
CVE-2022-22365
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Application Server versions 7.0 through 9.0
Description
The issue allows a man-in-the-middle attacker to spoof SSL server hostnames, enabling spoofing attacks. This is possible when the Ajax Proxy Web Application (AjaxProxy.war) is deployed.
Recommendations
For IBM WebSphere Application Server versions 7.0 through 9.0, consider disabling the Ajax Proxy Web Application (AjaxProxy.war) as a temporary workaround to minimize the risk of exploitation. Restrict access to sensitive resources to prevent man-in-the-middle attacks until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Websphere Application Server