IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6602015 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/225604 | vdb entry vendor advisory |