CVE-2022-22386 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2022-22386
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 221963. IBM Security Verify Privilege On-Premises 11.5 podría permitir que un atacante remoto obtenga información confidencial, causada por no habilitar correctamente HTTP Strict Transport Security. Un atacante podría aprovechar esta vulnerabilidad para obtener información confidencial utilizando técnicas de intermediario. • https://exchange.xforce.ibmcloud.com/vulnerabilities/221963 https://www.ibm.com/support/pages/node/7047202 • CWE-311: Missing Encryption of Sensitive Data •
CVE-2022-22384 – IBM Security Verify Privilege improper input validation
https://notcve.org/view.php?id=CVE-2022-22384
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due to hazardous input validation. IBM X-Force ID: 221961. IBM Security Verify Privilege On-Premises 11.5 podría permitir a un atacante modificar los mensajes devueltos por el servidor debido a una validación de entrada peligrosa. ID de IBM X-Force: 221961. • https://exchange.xforce.ibmcloud.com/vulnerabilities/221961 https://www.ibm.com/support/pages/node/7047202 • CWE-20: Improper Input Validation •
CVE-2022-22377 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2022-22377
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 221827. IBM Security Verify Privilege On-Premises 11.5 podría permitir que un atacante remoto obtenga información confidencial, causada por no habilitar correctamente HTTP Strict Transport Security. Un atacante podría aprovechar esta vulnerabilidad para obtener información confidencial utilizando técnicas de intermediario. • https://exchange.xforce.ibmcloud.com/vulnerabilities/221827 https://www.ibm.com/support/pages/node/7047202 • CWE-311: Missing Encryption of Sensitive Data •