CVE-2024-37532: IBM WebSphere Application Server identity spoofing
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.
Other sources
IBM WebSphere Application Server is vulnerable to identity spoofing by an authenticated user due to improper signature validation.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37532?
CVE-2024-37532 is classified as a high severity vulnerability due to the potential for identity spoofing by authenticated users.
How do I fix CVE-2024-37532?
To mitigate CVE-2024-37532, update IBM WebSphere Application Server to a patched version that addresses the improper signature validation issue.
Who is affected by CVE-2024-37532?
CVE-2024-37532 affects users of IBM WebSphere Application Server versions 8.5 and 9.0, including specific release versions 8.5.0.0 and 9.0.0.0.
What does CVE-2024-37532 exploit?
CVE-2024-37532 exploits improper signature validation which allows an authenticated user to spoof their identity.
Is CVE-2024-37532 related to other IBM vulnerabilities?
CVE-2024-37532 is a specific identity spoofing vulnerability but relates to broader security concerns regarding proper authentication mechanisms in IBM products.