Lucene search

K
ibmIBM7CEB92AF5112056EFB55497B890F0CC8AF75E571DE79A0265172F9759BB3AD91
HistoryOct 07, 2022 - 6:20 p.m.

Security Bulletin:IBM WebSphere Application Server, which is bundled with IBM WebSphere Hybrid Edition, is vulnerable to Server-Side Request Forgery (CVE-2022-35282)

2022-10-0718:20:05
www.ibm.com
7
ibm
websphere
hybrid edition
server-side request forgery
cve-2022-35282
vulnerability
security bulletin

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

17.7%

Summary

IBM WebSphere Application Server, which is bundled with IBM WebSphere Hybrid Edition, is vulnerable to Server-Side Request Forgery (CVE-2022-35282)

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) and Version(s) Affecting Product(s) and Version(s)

IBM WebSphere Hybrid Edition

  • 5.1
    |

IBM WebSphere Application Server

  • 9.0
  • 8.5
  • 8.0
  • 7.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the APAR PH47385 as desccribed in Security Bulletin: IBM WebSphere Application Server is vulnerable to Server-Side Request Forgery (CVE-2022-35282).

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmibm_websphere_hybrid_editionMatch5.1.0
VendorProductVersionCPE
ibmibm_websphere_hybrid_edition5.1.0cpe:2.3:a:ibm:ibm_websphere_hybrid_edition:5.1.0:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

17.7%

Related for 7CEB92AF5112056EFB55497B890F0CC8AF75E571DE79A0265172F9759BB3AD91