VDB
CVE-2022-34165
CVE-2022-34165
PUBLISHED
Es existiert eine Schwachstelle in IBM WebSphere Application Server. Nutzereingaben werden nur ungenügend validiert, was eine HTTP Header Injection ermöglicht. Ein authentisierter Angreifer kann diese Schwachstelle ausnutzen, um unterschiedliche Angriffe, wie z.B. Cache Poisoning oder Cross Site Scripting, auszuführen.
EPSS 0.24% · 47.0th percentile
Risk Scores
EPSS Score
0.24%
47.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| HCL | HCL BigFix 10.0.11 | |
| IBM | IBM InfoSphere Identity Insight 10.0 | |
| IBM | IBM License Metric Tool < 9.2.30 | |
| IBM | IBM Tivoli Monitoring | |
| IBM | IBM TXSeries for Multiplatforms 8.1 | |
| HCL | HCL Commerce 10.2.0 | |
| IBM | IBM Spectrum Protect Operations Center | |
| IBM | IBM WebSphere Application Server 7.0 | |
| IBM | IBM TXSeries for Multiplatforms 8.2 | |
| IBM | IBM Spectrum Protect for Space Management Client | |
| HCL | HCL AppScan Enterprise 10.2.0 | |
| IBM | IBM Security Verify Access 10.0.x | |
| IBM | IBM FileNet Content Manager 5.5.4 | |
| IBM | IBM SPSS | |
| IBM | IBM WebSphere Application Server 8.0 | |
| IBM | IBM Spectrum Scale | |
| IBM | IBM InfoSphere Identity Insight 9.1 | |
| IBM | IBM WebSphere Application Server 9.0 | |
| IBM | IBM InfoSphere Information Server 11.7 | |
| IBM | IBM InfoSphere Identity Insight 9.0 |
…and 8 more
Timeline
- Sep 7, 2022 CVE Published
- Sep 10, 2022 EPSS Score
- Oct 25, 2022 EPSS Score
- Dec 9, 2022 EPSS Score
- Jan 23, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 9, 2023 EPSS Score
- Apr 23, 2023 EPSS Score
- Jun 5, 2023 CVE Updated
- Jun 7, 2023 EPSS Score
- Jul 22, 2023 EPSS Score
- Sep 5, 2023 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2022-1342.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-1342 advisory
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0104902 advisory
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0104166 advisory
- https://www.ibm.com/support/pages/node/6618747 advisory
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-appliance-is-vulnerable-to-http-header-injection-cve-2022-34165/ advisory
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-affect-ibm-tivoli-monitoring-included-websphere-application-server-and-ibm-http-server-used-by-websphere-application-server-3/ advisory
- https://www.ibm.com/support/pages/node/6844859 advisory
- https://www.ibm.com/support/pages/node/6844721 advisory
- https://www.ibm.com/support/pages/node/6847655 advisory
- https://www.ibm.com/support/pages/node/6846533 advisory
- https://www.ibm.com/support/pages/node/6842075 advisory
- https://www.ibm.com/support/pages/node/6851953 advisory
- https://www.ibm.com/support/pages/node/6828833 advisory
- https://www.ibm.com/support/pages/node/6852709 advisory
- https://www.ibm.com/support/pages/node/6853379 advisory
- https://www.ibm.com/support/pages/node/6854451 advisory
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102570 advisory
- https://www.ibm.com/support/pages/node/6853357 advisory
- https://www.ibm.com/support/pages/node/6953617 advisory