Lucene search

K
ibmIBM81DF1271C980283EAE96E2EA68EE2FB4AF1499530A8B58708DB57556509A66CA
HistoryDec 06, 2022 - 3:23 p.m.

Security Bulletin: IBM Tivoli Composite Application Manager for Application Diagnostics Installed WebSphere Application Server is vulnerable to SOAPAction spoofing when processing JAX-WS Web Services requests (CVE-2022-38712)

2022-12-0615:23:01
www.ibm.com
5
ibm
tivoli composite
application diagnostics
soapaction spoofing
websphere application server
jax-ws
web services
cve-2022-38712

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

36.6%

Summary

The security issue described in CVE-2022-38712 has been identified in the WebSphere Application Server included as part of IBM Tivoli Composite Application Manager for Application Diagnostics

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
Tivoli Composite Application Manager for Application Diagnostics 7.1.0

Remediation/Fixes

Follow the WebSphere security bulletin, <https://www.ibm.com/support/pages/node/6829907&gt; to update WebSphere Application Servers.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmtivoli_composite_application_manager_for_wesbsphereMatch7.1.0

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

36.6%

Related for 81DF1271C980283EAE96E2EA68EE2FB4AF1499530A8B58708DB57556509A66CA