First published: Thu May 19 2022(Updated: )
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, is vulnerable to spoofing by allowing a man-in-the-middle attacker to spoof SSL server hostnames. IBM X-Force ID: 220904.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Application Server | >=7.0.0.0<=7.0.0.45 | |
Ibm Websphere Application Server | >=8.0.0.0<=8.0.0.15 | |
Ibm Websphere Application Server | >=8.5.0.0<=8.5.5.21 | |
Ibm Websphere Application Server | >=9.0.0.0<=9.0.5.11 | |
<=9.0 | ||
<=8.5 | ||
<=8.0 | ||
<=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-22365.
The severity of CVE-2022-22365 is medium with a severity value of 5.9.
IBM WebSphere Application Server is an application server that provides tools and technologies for building, deploying, and managing Java EE applications.
IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0 are affected by CVE-2022-22365.
An attacker can exploit CVE-2022-22365 by spoofing SSL server hostnames, allowing for man-in-the-middle attacks.