Potential Security Risk: HTTP Request Could Disclose Sensitive Information
CVE-2022-43890

7.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
4 March 2024

What is CVE-2022-43890?

A vulnerability exists in IBM Security Verify Privilege On-Premises 11.5 that allows for the potential disclosure of sensitive information through crafted HTTP requests. This flaw could facilitate further attacks, thereby compromising the integrity of the system. Organizations utilizing this version are advised to assess their security posture and apply necessary mitigations to safeguard sensitive data and reduce the risk of exploitation.

Affected Version(s)

Security Verify Privilege On-Premises 11.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.