CVE-2022-22365
Description
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, is vulnerable to spoofing by allowing a man-in-the-middle attacker to spoof SSL server hostnames. IBM X-Force ID: 220904.
CWE
- (none)
Affected
- IBM / WebSphere Application Server — v=7.0 [affected]; v=8.0 [affected]; v=8.5 [affected]; v=9.0 [affected]
CVSS
- 3.0 score=5.6 severity=MEDIUM
CVSS:3.0/I:L/A:L/S:U/AV:N/UI:N/C:L/AC:H/PR:N/RL:O/RC:C/E:U
References
- https://www.ibm.com/support/pages/node/6587947 x_refsource_CONFIRM
- https://exchange.xforce.ibmcloud.com/vulnerabilities/220904 vdb-entry, x_refsource_XF
Source
cvelistV5-main/cves/2022/22xxx/CVE-2022-22365.json