Potential Security Risk: HTTP Request Could Disclose Sensitive Information
CVE-2022-43890
5.3MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 4 March 2024
Summary
A vulnerability exists in IBM Security Verify Privilege On-Premises 11.5 that allows for the potential disclosure of sensitive information through crafted HTTP requests. This flaw could facilitate further attacks, thereby compromising the integrity of the system. Organizations utilizing this version are advised to assess their security posture and apply necessary mitigations to safeguard sensitive data and reduce the risk of exploitation.
Affected Version(s)
Security Verify Privilege On-Premises 11.5
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved