CVE-2022-34165: Medium severity ibm websphere application server feature pack for web services vulnerability
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct various attacks against the vulnerable system, including cache poisoning and cross-site scripting. IBM X-Force ID: 229429.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-34165?
CVE-2022-34165 is a vulnerability that affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0, as well as IBM WebSphere Application Server Liberty versions 17.0.0.3 through 22.0.0.9. It is caused by improper validation of HTTP headers and can allow various attacks against the system.
How severe is CVE-2022-34165?
CVE-2022-34165 has a severity rating of 5.4, which is considered medium.
How can I fix CVE-2022-34165?
To fix CVE-2022-34165, you should update your IBM WebSphere Application Server or IBM WebSphere Application Server Liberty to versions that are not affected by the vulnerability.
Where can I find more information about CVE-2022-34165?
You can find more information about CVE-2022-34165 on the IBM X-Force Exchange website and the IBM Support pages.
What is CWE-74?
CWE-74 refers to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection').