CVE-2022-43891: IBM Security Verify Privilege information disclosure
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-43891.
What is the title of the vulnerability?
The title of the vulnerability is IBM Security Verify Privilege On-Premises could allow a remote attacker to obtain sensitive information.
What is the severity of the vulnerability?
The severity of the vulnerability is low with a CVSS score of 2.7.
What is affected by this vulnerability?
IBM Security Verify Privilege On-Premises versions 11.5 and below are affected by this vulnerability.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by obtaining sensitive information from a detailed technical error message returned in the browser.