PT-2024-11578 · Ibm · Ibm Security Verify Directory

Ben Goodspeed

+8

·

Published

2024-03-22

·

Updated

2024-04-01

·

CVE-2022-32756

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Verify Directory version 10.0.0
Description The issue allows a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Recommendations For IBM Security Verify Directory version 10.0.0, upgrade immediately to a newer version to secure your data. As a temporary workaround, consider restricting access to detailed technical error messages to minimize the risk of exploitation.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-32756

Affected Products

Ibm Security Verify Directory