CVE-2022-22393
Description
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could allow an authenticated user to issue a request to obtain the status of HTTP/HTTPS ports which are accessible by the application server. IBM X-Force ID: 222078.
CWE
- (none)
Affected
- IBM / WebSphere Application Server Liberty — v=17.0.0.3 [affected]; v=22.0.0.5 [affected]
CVSS
- 3.0 score=3.1 severity=LOW
CVSS:3.0/A:N/AV:N/C:L/UI:N/I:N/S:U/PR:L/AC:H/E:U/RL:O/RC:C
References
- https://www.ibm.com/support/pages/node/6585704 x_refsource_CONFIRM
- https://exchange.xforce.ibmcloud.com/vulnerabilities/222078 vdb-entry, x_refsource_XF
Source
cvelistV5-main/cves/2022/22xxx/CVE-2022-22393.json