LiveActive security incident?Get immediate response
CVE Record

CVE-2022-22476: IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to ident...

IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.

MediumCVSS 5Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

An authenticated user may be able to spoof identity in affected IBM WebSphere Application Server Liberty and Open Liberty deployments using a specially crafted request. The issue is medium severity, but it matters where Liberty applications trust identity for access decisions or business workflows.

Executive priority

Treat this as a moderate-priority remediation item. It is not reported as actively exploited in the provided sources, but identity spoofing can undermine access control in business applications, especially on externally reachable Liberty services.

Technical view

CVE-2022-22476 is an identity spoofing vulnerability affecting IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty. The CVSS 3.0 score is 5.0 with network attack vector, low privileges required, no user interaction, high complexity, unchanged scope, and low confidentiality, integrity, and availability impacts.

Likely exposure

Exposure is likely limited to environments running the affected Liberty versions and allowing authenticated users to reach vulnerable application paths. Public exposure increases urgency, but the source bundle does not identify specific deployment configurations, endpoints, or application patterns required for impact.

Exploitation context

The provided sources describe exploitation by an authenticated user using a specially crafted request. There is no KEV listing and no cited source in the bundle confirms active exploitation, public exploit availability, or unauthenticated exploitation.

Researcher notes

Evidence is sparse in the provided bundle. IBM assigns X-Force ID 225604. The CVSS vector indicates authenticated network access, high attack complexity, and low CIA impacts. Avoid assuming affected configurations, exploit maturity, or specific fixed versions beyond vendor guidance.

Mitigation direction

  • Review IBM advisory guidance for CVE-2022-22476 and apply vendor-supported fixes.
  • Prioritize internet-facing or partner-facing Liberty deployments first.
  • Restrict authenticated access to Liberty applications where business need is limited.
  • Review identity-sensitive application controls for defense-in-depth.
  • Monitor IBM and Open Liberty advisories for affected-version clarification.

Validation and detection

  • Inventory WebSphere Application Server Liberty and Open Liberty versions.
  • Confirm whether versions fall within 17.0.0.3 through 22.0.0.7.
  • Identify applications where authenticated users influence identity context.
  • Check whether vendor remediation has been applied.
  • Review logs for unusual authenticated identity changes or access anomalies.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-22476 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/C:L/PR:L/A:L/AC:H/AV:N/UI:N/S:U/I:L/E:U/RL:O/RC:C

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5CVSS 3.0MediumCVSS:3.0/C:L/PR:L/A:L/AC:H/AV:N/UI:N/S:U/I:L/E:U/RL:O/RC:C1.63.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

5Medium
CVSS 3.0 vector shape for CVE-2022-22476Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/C:L/PR:L/A:L/AC:H/AV:N/UI:N/S:U/I:L/E:U/RL:O/RC:C

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
IBMWebSphere Application Server Liberty17.0.0.3, 22.0.0.7Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.