File Upload Vulnerability in IBM Security Verify Identity Manager
CVE-2022-22450

3.8LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
14 July 2022

Summary

IBM Security Verify Identity Manager version 10.0 is susceptible to a file upload vulnerability, which could be exploited by a privileged user to upload malicious files. This occurs due to inadequate security measures in handling file extensions within HTTP requests, potentially allowing unauthorized access and manipulation of sensitive data.

Affected Version(s)

Security Verify Governance 10.0

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.