PT-2022-24543 · Ibm · Ibm Websphere Application Server
Published
2022-11-03
·
Updated
2022-11-04
·
CVE-2022-38712
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Application Server versions 7.0 through 9.0
Description
The issue allows a man-in-the-middle attacker to conduct SOAPAction spoofing, potentially executing unwanted or unauthorized operations.
Recommendations
For versions 7.0 through 9.0, consider restricting access to Web services to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling Web services could help mitigate the risk.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Websphere Application Server