Inadequate Encryption Strength in IBM Security Verify Bridge for Directory Sync - CVE-2022-32753

 

Inadequate Encryption Strength in IBM Security Verify Bridge for Directory Sync - CVE-2022-32753

Published: April 23, 2024


Vulnerability identifier: #VU88906
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32753
CWE-ID: CWE-326
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker in the adjacent network to gain access to potentially sensitive information.

The vulnerability exists due to IBM Security Verify Directory uses weaker than expected cryptographic algorithms. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

IBM Security Verify Bridge for Directory Sync
IBM Security Verify Directory
IBM Security Directory Server
IBM Security Directory Suite

How to mitigate CVE-2022-32753

Install updates from vendor's website.

IBM Security Directory Server - update to 6.4.0.28
IBM Security Directory Suite - update to 8.0.1.21

External References

Related Security Bulletins