First published: Mon Jan 23 2023(Updated: )
IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information. This affects only the containerized version of WebSphere Application Server traditional. IBM X-Force ID: 241045.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server - traditional container | <=9.0 | |
IBM WebSphere Application Server - traditional container | <=8.5 | |
Ibm Websphere Application Server | =8.5 | |
Ibm Websphere Application Server | =9.0 | |
HP HP-UX | ||
IBM AIX | ||
IBM i | ||
Ibm Z\/os | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Oracle Solaris |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43917 refers to a vulnerability in IBM WebSphere Application Server traditional container that uses weaker than expected cryptographic keys, allowing an attacker to decrypt sensitive information.
IBM WebSphere Application Server versions 8.5 and 9.0 traditional container are affected by CVE-2022-43917.
CVE-2022-43917 has a severity rating of high, with a score of 7.5.
An attacker can exploit CVE-2022-43917 by using weaker cryptographic keys to decrypt sensitive information.
No, IBM WebSphere Application Server Liberty is not affected by CVE-2022-43917.