PT-2022-22686 · Ibm · Ibm Security Verify Information Queue

Ben Goodspeed

+8

·

Published

2022-07-25

·

Updated

2022-08-02

·

CVE-2022-35284

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Verify Information Queue version 10.0.2
Description The issue could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.
Recommendations For IBM Security Verify Information Queue version 10.0.2, consider setting the SameSite attribute for sensitive cookies to restrict access and minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-35284

Affected Products

Ibm Security Verify Information Queue