CVE-2022-38712: Medium severity ibm websphere application server feature pack for web services vulnerability
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762."
Other sources
IBM WebSphere Application Server Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-38712.
What is the severity of CVE-2022-38712?
The severity of CVE-2022-38712 is medium.
Which versions of IBM WebSphere Application Server are affected by CVE-2022-38712?
IBM WebSphere Application Server version 7.0, 8.0, 8.5, and 9.0 are affected by CVE-2022-38712.
What is the vulnerability description of CVE-2022-38712?
CVE-2022-38712 is a vulnerability in IBM WebSphere Application Server that could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations.
How can I fix CVE-2022-38712?
To fix CVE-2022-38712, update IBM WebSphere Application Server to a version that is not vulnerable.