Lucene search

K
ibmIBMEAADE4C7F0DED24F189CFA5CA05153CC52812144590071FE5628C90179377881
HistoryNov 03, 2022 - 3:14 p.m.

Security Bulletin: IBM WebSphere Application Server, which is bundled in IBM Cloud Pak for Applications, is vulnerable to SOAPAction spoofing (CVE-2022-38712)

2022-11-0315:14:48
www.ibm.com
4
ibm
websphere
application server
cloud pak
soapaction spoofing
cve-2022-38712

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

36.6%

Summary

IBM WebSphere Application Server, which is bundled in IBM Cloud Pak for Applications, is vulnerable to SOAPAction spoofing (CVE-2022-38712)

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) and Version(s) Affecting Product(s) and Version(s)

IBM Cloud Pak for Applications

  • 5.0
  • 5.1
    |

IBM WebSphere Application Server

  • 9.0
  • 8.5
  • 8.0
  • 7.0

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the APAR PH49111, as described in Security Bulletin: IBM WebSphere Application Server is vulnerable to SOAPAction spoofing (CVE-2022-38712).

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_pak_for_applicationsMatch5.0
OR
ibmcloud_pak_for_applicationsMatch5.1

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

36.6%

Related for EAADE4C7F0DED24F189CFA5CA05153CC52812144590071FE5628C90179377881