CVE-2022-22458: IBM Security Verify Governance, Identity Manager information disclosure
Published Dec 19, 2022
·Updated
IBM Security Verify Governance stores user credentials in plain clear text which can be read by a remote authenticated user.
Other sources
IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user. IBM X-Force ID: 225009.
Affected Software
3 affected components
IBM Security Verify Governance=10.0.1
Linux Linux kernel
IBM Security Verify Governance, Identity Manager virtual appliance component<=10.0.1
Remediation
Patch Available
Event History
Dec 19, 2022
CVE Published
via IBM·12:00 AM
Dec 22, 2022
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-22458?
The severity of CVE-2022-22458 is medium.
2
What does CVE-2022-22458 affect?
CVE-2022-22458 affects IBM Security Verify Governance, Identity Manager 10.0.1.
3
How are user credentials stored by CVE-2022-22458?
User credentials are stored in plain clear text by CVE-2022-22458.
4
Who can read the user credentials stored by CVE-2022-22458?
A remote authenticated user can read the user credentials stored by CVE-2022-22458.
5
Where can I find more information about CVE-2022-22458?
More information about CVE-2022-22458 can be found at the IBM X-Force ID: 225009.