PT-2022-15445 · Ibm · Ibm Security Verify Governance

Ben Goodspeed

+8

·

Published

2022-12-22

·

Updated

2022-12-28

·

CVE-2022-22457

CVSS v3.1

5.3

Medium

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Verify Governance, Identity Manager version 10.0.1
Description The issue allows a local privileged user to read sensitive information, including user credentials, stored in plain clear text.
Recommendations For IBM Security Verify Governance, Identity Manager version 10.0.1, consider restricting access to sensitive information to minimize the risk of exploitation until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-22457

Affected Products

Ibm Security Verify Governance