CVE-2022-22453: Weak Encryption
Published Jul 12, 2022
·Updated
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.
Other sources
IBM Security Verify Identity Manager uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
— IBM
Affected Software
3 affected components
IBM Security Verify Governance=10.0
Linux Linux kernel
IBM Security Verify Governance, Identity Manager virtual appliance component<=10.0
Remediation
Patch Available
Event History
Jul 12, 2022
CVE Published
via IBM·12:00 AM
Jul 14, 2022
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2022-22453.
2
What is the severity level of CVE-2022-22453?
The severity level of CVE-2022-22453 is high with a CVSS score of 7.5.
3
Which IBM product is affected by CVE-2022-22453?
IBM Security Verify Identity Manager 10.0 is affected by CVE-2022-22453.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability to decrypt highly sensitive information.
5
Are there any fixes or patches available for CVE-2022-22453?
It is recommended to apply the latest updates and patches provided by IBM to mitigate this vulnerability.