IBM Security Directory Integrator Vulnerability
CVE-2022-33167
7.5HIGH
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 30 July 2024
Summary
A vulnerability exists in IBM Security Directory Integrator and IBM Security Verify Directory Integrator that allows attackers to gain unauthorized access to sensitive information. This arises from a failure to properly implement the HTTPOnly flag, which can leave vulnerable cookies accessible to remote attackers. By exploiting this issue, attackers could potentially retrieve sensitive data from cookies, posing significant risks to user privacy and data integrity. Organizations using affected versions should prioritize timely updates and mitigations to safeguard sensitive information.
Affected Version(s)
Security Directory Integrator 7.2.0
Security Verify Directory Integrator 10.0.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved