MEDIUM
IBM Security Directory Server information disclosure
Published Oct 14, 2023
5.9
MEDIUMCVSS 3.1
EPSS 0.55%
Description
IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.
Affected products
-
- Version 6.4.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| IBM | Security Directory Server | unaffected |
|
OR
- 7.2.0
- 6.4.0.0
- 8.0.1
- 10.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-36206 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/228569 vdb-entryVDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/7047116 vendor-advisoryPatchVendor Advisory
- https://www.ibm.com/support/pages/node/7047428 vendor-advisoryPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-36206 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/228569 | vdb-entryVDB EntryVendor Advisory | |
| https://www.ibm.com/support/pages/node/7047116 | vendor-advisoryPatchVendor Advisory | |
| https://www.ibm.com/support/pages/node/7047428 | vendor-advisoryPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Oct 14, 2023
Updated Sep 16, 2024
Reserved Jun 13, 2022
Link CVE-2022-33161
CISA Vulnrichment
Updated Sep 16, 2024
ENISA EUVD
EUVD-2022-36206 Assigner ibm
Published Oct 14, 2023
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2022-36206