Cross-Site Request Forgery Vulnerability in IBM Security Verify Information Queue
CVE-2022-35286

3.1LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
26 July 2022

Summary

IBM Security Verify Information Queue version 10.0.2 is susceptible to a cross-site request forgery (CSRF) attack. This vulnerability can enable malicious actors to perform unauthorized actions on behalf of a trusted user, exploiting the trust relationship established by the website. It is imperative for users of the affected version to implement safeguards to mitigate the risk of such attacks.

Affected Version(s)

Security Verify Information Queue 10.0.2

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.