CVE-2022-43917
Published on: Not Yet Published
Last Modified on: 02/01/2023 08:44:00 PM UTC
Certain versions of Hp-ux from Hp contain the following vulnerability:
IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information. This affects only the containerized version of WebSphere Application Server traditional. IBM X-Force ID: 241045.
- CVE-2022-43917 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
IBM - WebSphere Application Server version = 8.5, 9.0
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Bulletin: IBM WebSphere Application Server traditional container is vulnerable to information disclosure (CVE-2022-43917) | www.ibm.com text/html |
![]() |
IBM X-Force Exchange | exchange.xforce.ibmcloud.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that …
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Hp | Hp-ux | - | All | All | All |
Operating System | Ibm | Aix | - | All | All | All |
Operating System | Ibm | I | - | All | All | All |
Application | Ibm | Websphere Application Server | 8.5 | All | All | All |
Application | Ibm | Websphere Application Server | 9.0 | All | All | All |
Operating System | Ibm | Z/os | - | All | All | All |
Operating System | Linux | Linux Kernel | - | All | All | All |
Operating System | Microsoft | Windows | - | All | All | All |
Operating System | Oracle | Solaris | - | All | All | All |
- cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*:
- cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*:
- cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:traditional:*:*:*:
- cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:traditional:*:*:*:
- cpe:2.3:o:ibm:z\/os:-:*:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
- cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:-:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-43917 : #IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryp… twitter.com/i/web/status/1… | 2023-01-26 21:22:57 |