Information Exposure Through an Error Message in IBM Security Verify Bridge for Directory Sync - CVE-2022-32756
Published: April 23, 2024
Vulnerability identifier: #VU88905
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32756
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote privileged user can gain unauthorized access to sensitive information on the system when a detailed technical error message is returned in the browser.
Affected software
IBM Security Verify Bridge for Directory Sync
IBM Security Verify Directory
IBM Security Directory Server
IBM Security Verify Directory
IBM Security Directory Server
How to mitigate CVE-2022-32756
Install updates from vendor's website.
IBM Security Directory Server - update to 6.4.0.28