CVE-2022-22457: IBM Security Verify Governance, Identity Manager information disclosure
IBM Security Verify Governance stores sensitive information including user credentials in plain clear text which can be read by a local privileged user.
Other sources
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22457?
The severity of CVE-2022-22457 is medium with a CVSS score of 5.3.
What is the impact of CVE-2022-22457?
CVE-2022-22457 allows a local privileged user to read sensitive information including user credentials stored in plain clear text.
Which software versions are affected by CVE-2022-22457?
IBM Security Verify Governance version 10.0.1 is affected by CVE-2022-22457.
How can I mitigate CVE-2022-22457?
There is currently no known mitigation for CVE-2022-22457. It is recommended to apply the latest security updates when they become available.
Where can I find more information about CVE-2022-22457?
More information about CVE-2022-22457 can be found at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/225007), [Reference 2](https://www.ibm.com/support/pages/node/6849247)