Lucene search

K
cveIbmCVE-2022-43889
HistoryOct 17, 2023 - 2:15 a.m.

CVE-2022-43889

2023-10-1702:15:10
CWE-200
ibm
web.nvd.nist.gov
30
ibm
security
verify
privilege
on-premises
11.5
vulnerability
cve-2022-43889
nvd
ibm x-force id
240452
information disclosure
http request
attack

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.8

Confidence

High

EPSS

0

Percentile

13.1%

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240452.

Affected configurations

Nvd
Vulners
Node
applemacosMatch-
OR
microsoftwindowsMatch-
AND
ibmsecurity_verify_privilege_on-premisesRange<11.5
VendorProductVersionCPE
applemacos-cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
ibmsecurity_verify_privilege_on-premises*cpe:2.3:a:ibm:security_verify_privilege_on-premises:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Security Verify Privilege",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "11.5"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

4.8

Confidence

High

EPSS

0

Percentile

13.1%

Related for CVE-2022-43889