CVE-2022-22452: High severity ibm security verify governance - identity manager vulnerability
IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918.
Other sources
IBM Security Verify Identity Manager uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-22452?
CVE-2022-22452 is a vulnerability in IBM Security Verify Identity Manager 10.0 that allows a remote attacker to brute force account credentials.
What is the severity of CVE-2022-22452?
The severity of CVE-2022-22452 is high, with a severity value of 7.5.
Which software is affected by CVE-2022-22452?
IBM Security Verify Governance, Identity Manager virtual appliance component version 10.0 is affected by CVE-2022-22452.
How can CVE-2022-22452 be exploited?
CVE-2022-22452 can be exploited by a remote attacker who can perform brute force attacks to guess account credentials.
Is there a fix available for CVE-2022-22452?
Please refer to the IBM Security Verify Identity Manager documentation or contact IBM Support for information on how to mitigate CVE-2022-22452.