Denial of Service Vulnerability in IBM Security Identity Manager Password Synch Plug-in
CVE-2022-22312
5.7MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 27 April 2022
Summary
IBM Security Verify Password Synchronization Plug-in for Windows Active Directory versions 10.x has a vulnerability that allows authenticated attackers to exploit a heap-based buffer overflow. This exploitation can lead to a denial of service, disrupting the functionality of the service. Users are advised to apply the appropriate updates to maintain the security of their systems. Detailed information can be found through the IBM support page and vulnerability database.
Affected Version(s)
Security Verify Password Synchronization Plug-in for Windows AD 10.0.0
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved