HTTP/HTTPS Port Status Exposure in IBM WebSphere Application Server Liberty
CVE-2022-22393
3.1LOW
What is CVE-2022-22393?
The IBM WebSphere Application Server Liberty, when configured with the adminCenter-1.0 feature, exposes a vulnerability that potentially allows authenticated users to request and obtain the status of accessible HTTP/HTTPS ports. This exposure could facilitate unauthorized insights into the server's network services, leading to potential security risks.
Affected Version(s)
WebSphere Application Server Liberty 17.0.0.3
WebSphere Application Server Liberty 22.0.0.5