IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "17.0.0.3"
},
{
"fixed": "22.0.0.8"
}
],
"source": "CPE_RANGE",
"vendor_product": "ibm:websphere_application_server",
"cpes": [
"cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:liberty:*:*:*"
]
}
]
}