File Upload Vulnerability in IBM Security Verify Identity Manager
CVE-2022-22450
3.8LOW
Summary
IBM Security Verify Identity Manager version 10.0 is susceptible to a file upload vulnerability, which could be exploited by a privileged user to upload malicious files. This occurs due to inadequate security measures in handling file extensions within HTTP requests, potentially allowing unauthorized access and manipulation of sensitive data.
Affected Version(s)
Security Verify Governance 10.0
References
CVSS V3.1
Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved