CVE-2024-22329: IBM WebSphere Application Server server-side request forgery
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to conduct the SSRF attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22329?
CVE-2024-22329 is classified as a high severity vulnerability due to its potential for server-side request forgery (SSRF) attacks.
How do I fix CVE-2024-22329?
To fix CVE-2024-22329, update IBM WebSphere Application Server to the latest version provided by IBM.
Which IBM products are affected by CVE-2024-22329?
CVE-2024-22329 affects IBM WebSphere Application Server versions 8.5, 9.0, and Liberty versions 17.0.0.3 through 24.0.0.3.
What types of attacks can exploit CVE-2024-22329?
CVE-2024-22329 can be exploited through server-side request forgery (SSRF) attacks.
Is there a workaround for CVE-2024-22329?
Currently, the recommended mitigation for CVE-2024-22329 is to apply software updates as no specific workarounds have been documented.