IBM Support

PH50116:IBM WebSphere Application Server is vulnerable to Cross-site Scripting (CVE-2022-22477 CVSS 6.1)

Download


Downloadable File

File link File size File description

Abstract

IBM WebSphere Application Server is vulnerable to Cross-site Scripting (CVE-2022-22477 CVSS 6.1)

Download Description


This interim fix supersedes the fixes for PH46332
The interim fixes on this page supersede the fixes for APAR PH46332. If you previously downloaded and installed a fix for APAR PH46332, you must download and install a fix for PH50116 to get a complete solution for CVE-2022-22477. 
If you already have a fix for PH46332 installed, there is no need to uninstall it before installing a fix for PH50116.

PH50116 resolves the following problem:

ERROR DESCRIPTION:
Confidential for Security Integrity interim fix CVE-2022-22477.

PROBLEM SUMMARY:
Confidential for Security Integrity interim fix CVE-2022-22477.

PROBLEM CONCLUSION:
Confidential for CVE-2022-22477.

The fix for this APAR is currently targeted for inclusion in fix packs 8.5.5.23 and 9.0.5.14.

For more information, see 'Recommended Updates for WebSphere Application Server':
http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980

This fix supersedes (includes) the fix for PH01621, PH46332

Prerequisites

None

Installation Instructions

Review the readme.txt for detailed installation instructions.

 
URL SIZE(Bytes)
V85 IM readme file 2412
V90 IM readme file 2345

Download Package

 
IMPORTANT NOTE:
WebSphere Application Server and Liberty fix access requires S&S Entitlement beginning in 2021. Use properly registered IDs to download the fixes in this table. 
DOWNLOAD RELEASE DATE SIZE(Bytes)

URL

8.5.5.0-WS-WASProd-IFPH50116 18 October 2022 292036 FC
9.0.0.0-WS-WASProd-IFPH50116 18 October 2022 295566 FC
Note: FC stands for Fix Central. Review the What is Fix Central (FC)? FAQs for more details.

Problems Solved

PH50116, PH01621, PH46332

On

Technical Support

Contact IBM Support at https://www.ibm.com/mysupport/ or 1-800-IBM-SERV (US only).

Document Location

Worldwide

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Component":"General","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF012","label":"IBM i"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"8.5.5.22;8.5.5.21;8.5.5.20;8.5.5.19;8.5.5.18;8.5.5.17;8.5.5.16;8.5.5.15;8.5.5.14;8.5.5.13;8.5.5.12;8.5.5.11;8.5.5.10;8.5.5.9;8.5.5.8;8.5.5.7;8.5.0.2;8.5.0.1;8.5;9.0.5.13;9.0.5.12;9.0.5.11;9.0.5.10;9.0.5.9;9.0.5.8;9.0.5.7;9.0.5.6;9.0.5.5;9.0.5.4;9.0.5.3;9.0.5.2;9.0.5.1;9.0.5.0;9.0.0.11;9.0.0.10;9.0.0.9;9.0.0.8;9.0.0.7;9.0.0.6;9.0.0.5;9.0.0.4;9.0.0.3;9.0.0.2;8.5.5.6;8.5.5.5;8.5.5.4;8.5.5.3;8.5.5.2;8.5.5.1;8.5.5;9.0.0.1;9.0.0.0","Edition":"Base","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
20 October 2022

UID

ibm16830625