Subscribe to this APAR
Subscribe to this APAR
IBM WebSphere Application Server is vulnerable to SOAPAction spoofing when processing JAX-WS Web Services requests.This has been addressed.
CVEID: CVE-2022-38712[1]
DESCRIPTION: IBM WebSphere Application
Server Web services could allow a man-in-the-middle attacker to
conduct SOAPAction spoofing to execute unwanted or unauthorized
operations.
CVSS Base score:5.9
CVSS Temporal Score:See:https://exchange.xforce.ibmcloud.com/vulnerabilities/234762[2]
for the current score.
...
Weitere Beiträge ...
- WebSphere Application Server HTTP plug-in problems on IBM i (i5/OS)
- SSL CONFIGURATION BUILT FROM JVM PROPERTIES NOT TAKING FIPS INTO ACCOUNT WHEN FILLING IN SSL PROTOCOL.
- PH49906: LB'S PROMISCOUS SETTING IS NOT HONORED WHEN CONFIGURED IN LBEXECUTOR.CONF
- LB'S PROMISCOUS SETTING IS NOT HONORED WHEN CONFIGURED IN LBEXECUTOR.CONF
Seite 26 von 48