Use of a broken or risky cryptographic algorithm in IBM Sterling External Authentication Server and IBM Sterling Secure Proxy - CVE-2022-35720
Published: September 21, 2023
Vulnerability identifier: #VU81037
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-35720
CWE-ID: CWE-327
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A local user can gain unauthorized access to sensitive information on the system.
Affected software
IBM Sterling External Authentication Server
IBM Sterling Secure Proxy
IBM Sterling Secure Proxy
How to mitigate CVE-2022-35720
Install updates from vendor's website.
IBM Sterling External Authentication Server - update to 6.1.0.0 iFix02
IBM Sterling Secure Proxy - update to 6.0.3 iFix 06
IBM Sterling Secure Proxy - update to 6.0.3 iFix 06