Lucene search

K
ibmIBMA56E9A1A53ADE0BF29C8D12FA64E1C1C50CB88BE88908F2EC8BAD25C5B7838E3
HistoryOct 20, 2022 - 3:17 p.m.

Security Bulletin: Vulnerability identified in IBM WebSphere Application Server shipped with IBM WebSphere Service Registry and Repository (CVE-2022-38712)

2022-10-2015:17:36
www.ibm.com
12
ibm websphere
service registry
repository
vulnerability
soapaction spoofing
cve-2022-38712

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

26.3%

Summary

IBM WebSphere Application Server is shipped as a component of IBM WebSphere Service Registry and Repository. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Principal Product and Version(s) Affected Supporting Product and Version(s)
WebSphere Service Registry and Repository V8.5 WebSphere Application Server V8.5.5
WebSphere Service Registry and Repository V8.0 WebSphere Application Server V8.0

Remediation/Fixes

Please consult the security bulletin:

Security Bulletin: IBM WebSphere Application Server is vulnerable to SOAPAction spoofing (CVE-2022-38712)

for vulnerability details and information about fixes.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmwebsphere_service_registry_and_repositoryMatch8.0
OR
ibmwebsphere_service_registry_and_repositoryMatch8.5
VendorProductVersionCPE
ibmwebsphere_service_registry_and_repository8.0cpe:2.3:a:ibm:websphere_service_registry_and_repository:8.0:*:*:*:*:*:*:*
ibmwebsphere_service_registry_and_repository8.5cpe:2.3:a:ibm:websphere_service_registry_and_repository:8.5:*:*:*:*:*:*:*

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

26.3%

Related for A56E9A1A53ADE0BF29C8D12FA64E1C1C50CB88BE88908F2EC8BAD25C5B7838E3