Security readout for executives and security teams
Plain-English summary
An authenticated user may be able to spoof identity in affected IBM WebSphere Application Server Liberty and Open Liberty deployments using a specially crafted request. The issue is medium severity, but it matters where Liberty applications trust identity for access decisions or business workflows.
Executive priority
Treat this as a moderate-priority remediation item. It is not reported as actively exploited in the provided sources, but identity spoofing can undermine access control in business applications, especially on externally reachable Liberty services.
Technical view
CVE-2022-22476 is an identity spoofing vulnerability affecting IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty. The CVSS 3.0 score is 5.0 with network attack vector, low privileges required, no user interaction, high complexity, unchanged scope, and low confidentiality, integrity, and availability impacts.
Likely exposure
Exposure is likely limited to environments running the affected Liberty versions and allowing authenticated users to reach vulnerable application paths. Public exposure increases urgency, but the source bundle does not identify specific deployment configurations, endpoints, or application patterns required for impact.
Exploitation context
The provided sources describe exploitation by an authenticated user using a specially crafted request. There is no KEV listing and no cited source in the bundle confirms active exploitation, public exploit availability, or unauthenticated exploitation.
Researcher notes
Evidence is sparse in the provided bundle. IBM assigns X-Force ID 225604. The CVSS vector indicates authenticated network access, high attack complexity, and low CIA impacts. Avoid assuming affected configurations, exploit maturity, or specific fixed versions beyond vendor guidance.
Mitigation direction
- Review IBM advisory guidance for CVE-2022-22476 and apply vendor-supported fixes.
- Prioritize internet-facing or partner-facing Liberty deployments first.
- Restrict authenticated access to Liberty applications where business need is limited.
- Review identity-sensitive application controls for defense-in-depth.
- Monitor IBM and Open Liberty advisories for affected-version clarification.
Validation and detection
- Inventory WebSphere Application Server Liberty and Open Liberty versions.
- Confirm whether versions fall within 17.0.0.3 through 22.0.0.7.
- Identify applications where authenticated users influence identity context.
- Check whether vendor remediation has been applied.
- Review logs for unusual authenticated identity changes or access anomalies.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2022-22476 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/C:L/PR:L/A:L/AC:H/AV:N/UI:N/S:U/I:L/E:U/RL:O/RC:C
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/C:L/PR:L/A:L/AC:H/AV:N/UI:N/S:U/I:L/E:U/RL:O/RC:C1.63.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
5MediumVector: CVSS:3.0/C:L/PR:L/A:L/AC:H/AV:N/UI:N/S:U/I:L/E:U/RL:O/RC:C
Source materials
- CVE List V5 sourceCVE List V5
- https://www.ibm.com/support/pages/node/6602015CVE reference · x_refsource_CONFIRM
- ibm-websphere-cve202222476-spoofing (225604)CVE reference · vdb-entry, x_refsource_XF
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
