First published: Thu Mar 21 2024(Updated: )
IBM Security Directory Server could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Directory | <=10.0.0 | |
IBM Security Verify Directory | =10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32756 has a medium severity level due to the potential for sensitive information disclosure.
To fix CVE-2022-32756, upgrade IBM Security Verify Directory to a version higher than 10.0.0.
CVE-2022-32756 affects IBM Security Verify Directory version 10.0.0.
An attacker could use the sensitive information obtained from CVE-2022-32756 for further targeted attacks on the system.
Mitigation for CVE-2022-32756 includes limiting the exposure of detailed error messages to the public and implementing security best practices.