PT-2023-7012 · Ibm · Ibm Security Verify Privilege On-Premises

CVE-2022-22377

·

Publicado

2023-10-16

·

Atualizado

2023-10-18

CVSS v2.0

5.4

Média

VetorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Verify Privilege On-Premises version 11.5
Description The issue is related to the lack of data encryption measures in IBM Security Verify Privilege On-Premises, which could allow a remote attacker to obtain sensitive information by exploiting the failure to properly enable HTTP Strict Transport Security. This could enable an attacker to conduct "man in the middle" attacks.
Recommendations For IBM Security Verify Privilege On-Premises version 11.5, enable HTTP Strict Transport Security to prevent exploitation of this issue. As a temporary workaround, consider restricting access to sensitive information until the issue is resolved.

Correção

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08032
CVE-2022-22377

Produtos afetados

Ibm Security Verify Privilege On-Premises