Sensitive Information Disclosure in IBM Security Verify Information Queue
CVE-2022-35284
5.3MEDIUM
Summary
IBM Security Verify Information Queue version 10.0.2 contains a vulnerability that may enable unauthorized disclosure of sensitive information. This occurs due to a missing or improperly configured SameSite attribute for critical cookies, potentially exposing data during cross-site requests. Organizations utilizing this software should take immediate action to review their cookie configurations to mitigate the risk associated with this vulnerability.
Affected Version(s)
Security Verify Information Queue 10.0.2
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved