SB2023012448 - Information disclosure in IBM WebSphere Application Server



SB2023012448 - Information disclosure in IBM WebSphere Application Server

Published: January 24, 2023

Security Bulletin ID SB2023012448
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Inadequate Encryption Strength (CVE-ID: CVE-2022-43917)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to the IBM WebSphere Application Server traditional container uses weaker than expected cryptographic keys that could allow an attacker to decrypt sensitive information.A remote attacker can gain access to sensitive information.

Note, this affects only the containerized version of WebSphere Application Server traditional.


Remediation

Install update from vendor's website.