CVE-2022-43917
Last modified
CVE-2022-43917 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information. This affects only the containerized version of WebSphere Application Server traditional. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information. This affects only the containerized version of WebSphere Application Server traditional. IBM X-Force ID: 241045.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Websphere Application Server | 8.5 |
| Ibm | Websphere Application Server | 9.0 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/241045VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6857007Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/241045VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/6857007Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-43917?
How severe is CVE-2022-43917?
How do I fix CVE-2022-43917?
Are you affected by CVE-2022-43917?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
