CVE-2022-43906: IBM Security Guardium information disclosure
Published Oct 4, 2023
·Updated
IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. IBM X-Force ID: 240897.
Affected Software
2 affected components
IBM Security Guardium=11.5
Linux Linux kernel
Remediation
Patch Available
Event History
Oct 4, 2023
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2022-43906.
2
What is the title of this vulnerability?
The title of this vulnerability is 'IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie.'
3
What is the affected software?
The affected software is IBM Security Guardium 11.5.
4
What is the severity of CVE-2022-43906?
The severity of CVE-2022-43906 is medium.
5
How can I fix this vulnerability?
To fix this vulnerability, apply the necessary patch or upgrade to IBM Security Guardium 11.5 with the secure SameSite attribute for the sensitive cookie.