IBM Security Directory Integrator Vulnerability
CVE-2022-33167
7.5HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 30 July 2024
What is CVE-2022-33167?
A vulnerability exists in IBM Security Directory Integrator and IBM Security Verify Directory Integrator that allows attackers to gain unauthorized access to sensitive information. This arises from a failure to properly implement the HTTPOnly flag, which can leave vulnerable cookies accessible to remote attackers. By exploiting this issue, attackers could potentially retrieve sensitive data from cookies, posing significant risks to user privacy and data integrity. Organizations using affected versions should prioritize timely updates and mitigations to safeguard sensitive information.
Affected Version(s)
Security Directory Integrator 7.2.0
Security Verify Directory Integrator 10.0.0