First published: Mon Dec 19 2022(Updated: )
IBM Security Verify Governance stores sensitive information including user credentials in plain clear text which can be read by a local privileged user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Governance | =10.0.1 | |
Linux Linux kernel | ||
<=10.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22457 is medium with a CVSS score of 5.3.
CVE-2022-22457 allows a local privileged user to read sensitive information including user credentials stored in plain clear text.
IBM Security Verify Governance version 10.0.1 is affected by CVE-2022-22457.
There is currently no known mitigation for CVE-2022-22457. It is recommended to apply the latest security updates when they become available.
More information about CVE-2022-22457 can be found at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/225007), [Reference 2](https://www.ibm.com/support/pages/node/6849247)