Description
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 228587.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-36212 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 228587. |
References
History
Tue, 13 Aug 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ibm
Ibm security Directory Integrator Ibm security Verify Directory Integrator |
|
| Weaknesses | CWE-732 | |
| CPEs | cpe:2.3:a:ibm:security_directory_integrator:7.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_verify_directory_integrator:10.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm security Directory Integrator Ibm security Verify Directory Integrator |
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-03T08:01:20.017Z
Reserved: 2022-06-13T16:18:00.249Z
Link: CVE-2022-33167
Updated: 2024-08-03T08:01:20.017Z
Status : Modified
Published: 2024-07-30T17:15:10.020
Modified: 2024-11-21T07:07:38.277
Link: CVE-2022-33167
No data.
OpenCVE Enrichment
No data.
EUVD