First published: Tue May 17 2022(Updated: )
IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM X-Force ID: 225603.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Open Liberty | >=17.0.0.3<=22.0.0.5 | |
Ibm Websphere Application Server | >=17.0.0.3<=22.0.0.5 | |
IBM Security Verify Access Docker | <=10.0.X | |
IBM Security Verify Access | <=10.0.X |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22475 is high with a CVSS score of 7.1.
An authenticated user can exploit CVE-2022-22475 by impersonating another user.
IBM WebSphere Application Server Liberty and Open Liberty versions 17.0.0.3 through 22.0.0.5 are affected by CVE-2022-22475.
To fix CVE-2022-22475, IBM recommends updating to a fixed version of IBM WebSphere Application Server Liberty or Open Liberty.
You can find more information about CVE-2022-22475 on the IBM X-Force Exchange website or the IBM support pages.