First published: Wed Jul 24 2024(Updated: )
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Directory Integrator | <=7.2.0 | |
IBM Security Verify Directory Integrator | <=10.0.0 | |
IBM Security Directory Integrator | =7.2.0 | |
IBM Security Directory Server | ||
IBM Security Verify Access | =10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32759 has a medium severity rating due to its potential to allow unauthorized access to sensitive information.
To fix CVE-2022-32759, update IBM Security Directory Integrator to version 7.2.1 or later and IBM Security Verify Directory Integrator to version 10.0.1 or later.
CVE-2022-32759 affects IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0.
Yes, due to insufficient session expiration, CVE-2022-32759 could potentially lead to unauthorized access and data breaches.
The risks associated with CVE-2022-32759 include exposure of sensitive information and possible unauthorized actions by attackers.