CVE-2022-22470: IBM Security Verify Governance information disclosure
Published Jan 5, 2023
·Updated
IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225232.
Other sources
IBM Security Verify Governance stores user credentials in plain clear text which can be read by a local user.
— IBM
Affected Software
2 affected components
IBM Security Verify Governance=10.0
IBM Security Verify Governance<=10.0
Remediation
Patch Available
Event History
Jan 5, 2023
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Jan 6, 2023
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-22470?
The severity of CVE-2022-22470 is medium with a severity value of 5.5.
2
How can a local user read user credentials in IBM Security Verify Governance?
A local user can read user credentials in IBM Security Verify Governance as they are stored in plain clear text.
3
What is the IBM X-Force ID for CVE-2022-22470?
The IBM X-Force ID for CVE-2022-22470 is 225232.
4
How can I determine if my version of IBM Security Verify Governance is affected by CVE-2022-22470?
If you are using IBM Security Verify Governance version 10.0, your system is affected by CVE-2022-22470.
5
Is there a fix available for CVE-2022-22470?
Please refer to the IBM Security Verify Governance support page for information on available fixes for CVE-2022-22470.