First published: Wed Apr 17 2024(Updated: )
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to conduct the SSRF attack.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Governance | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22329 is classified as a high severity vulnerability due to its potential for server-side request forgery (SSRF) attacks.
To fix CVE-2024-22329, update IBM WebSphere Application Server to the latest version provided by IBM.
CVE-2024-22329 affects IBM WebSphere Application Server versions 8.5, 9.0, and Liberty versions 17.0.0.3 through 24.0.0.3.
CVE-2024-22329 can be exploited through server-side request forgery (SSRF) attacks.
Currently, the recommended mitigation for CVE-2024-22329 is to apply software updates as no specific workarounds have been documented.