CVE-2022-22475: High severity ibm security verify access vulnerability
Published May 17, 2022
·Updated
IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM X-Force ID: 225603.
Affected Software
4 affected components
IBM Security Verify Access Docker<=10.0.X
IBM Security Verify Access<=10.0.X
IBM Open Liberty>=17.0.0.3<=22.0.0.5
IBM WebSphere Application Server>=17.0.0.3<=22.0.0.5
Remediation
Patch Available
Event History
May 16, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-22475?
The severity of CVE-2022-22475 is high with a CVSS score of 7.1.
2
How can an authenticated user exploit CVE-2022-22475?
An authenticated user can exploit CVE-2022-22475 by impersonating another user.
3
Which versions of IBM WebSphere Application Server Liberty and Open Liberty are affected by CVE-2022-22475?
IBM WebSphere Application Server Liberty and Open Liberty versions 17.0.0.3 through 22.0.0.5 are affected by CVE-2022-22475.
4
How can I fix CVE-2022-22475?
To fix CVE-2022-22475, IBM recommends updating to a fixed version of IBM WebSphere Application Server Liberty or Open Liberty.
5
Where can I find more information about CVE-2022-22475?
You can find more information about CVE-2022-22475 on the IBM X-Force Exchange website or the IBM support pages.