First published: Wed Jan 17 2024(Updated: )
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240453.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Privilege Vault Remote On-premises | <=11.5 and earlier | |
IBM Security Verify Privilege Vault Remote On-premises | <=11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43890 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2022-43890, upgrade IBM Security Verify Privilege On-Premises to version 11.6 or later, which addresses this vulnerability.
CVE-2022-43890 affects IBM Security Verify Privilege On-Premises versions 11.5 and earlier.
CVE-2022-43890 is a sensitive information disclosure vulnerability that can help attackers in further exploitation.
Yes, CVE-2022-43890 can be exploited remotely through crafted HTTP requests.