PT-2023-7012 · Ibm · Ibm Security Verify Privilege On-Premises

Published

2023-10-16

·

Updated

2023-10-18

·

CVE-2022-22377

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Verify Privilege On-Premises version 11.5
Description The issue is related to the lack of data encryption measures in IBM Security Verify Privilege On-Premises, which could allow a remote attacker to obtain sensitive information by exploiting the failure to properly enable HTTP Strict Transport Security. This could enable an attacker to conduct "man in the middle" attacks.
Recommendations For IBM Security Verify Privilege On-Premises version 11.5, enable HTTP Strict Transport Security to prevent exploitation of this issue. As a temporary workaround, consider restricting access to sensitive information until the issue is resolved.

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

BDU:2023-08032
CVE-2022-22377

Affected Products

Ibm Security Verify Privilege On-Premises