Denial of Service Vulnerability in IBM Security Identity Manager Password Synch Plug-in
CVE-2022-22312

5.7MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
27 April 2022

Summary

IBM Security Verify Password Synchronization Plug-in for Windows Active Directory versions 10.x has a vulnerability that allows authenticated attackers to exploit a heap-based buffer overflow. This exploitation can lead to a denial of service, disrupting the functionality of the service. Users are advised to apply the appropriate updates to maintain the security of their systems. Detailed information can be found through the IBM support page and vulnerability database.

Affected Version(s)

Security Verify Password Synchronization Plug-in for Windows AD 10.0.0

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.