CVE-2022-22449: IBM Security Verify Governance, Identity Manager information disclosure
IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 224915.
Other sources
IBM Security Verify Identity Manager could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-22449.
What is the severity of CVE-2022-22449?
The severity of CVE-2022-22449 is medium.
How does the vulnerability impact IBM Security Verify Identity Manager?
The vulnerability allows a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser, which could be used in further attacks against the system.
Which versions of IBM Security Verify Governance, Identity Manager are affected by CVE-2022-22449?
IBM Security Verify Governance, Identity Manager version 10.0.1 is affected by CVE-2022-22449.
How can I fix CVE-2022-22449?
IBM has released a security advisory with remediation steps to address this vulnerability. Please refer to the IBM support page for more information.