CVE-2022-43917
Summary
| CVE | CVE-2022-43917 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-26 21:17:00 UTC |
| Updated | 2023-11-07 03:54:00 UTC |
| Description | IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information. This affects only the containerized version of WebSphere Application Server traditional. IBM X-Force ID: 241045. |
Risk And Classification
Problem Types: CWE-327
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Hp | Hp-ux | - | All | All | All |
| Operating System | Ibm | Aix | - | All | All | All |
| Operating System | Ibm | I | - | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5 | All | All | All |
| Application | Ibm | Websphere Application Server | 9.0 | All | All | All |
| Operating System | Ibm | Z/os | - | All | All | All |
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Oracle | Solaris | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: IBM WebSphere Application Server traditional container is vulnerable to information disclosure (CVE-2022-43917) | MISC | www.ibm.com | |
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.