Rewterz
Rewterz Threat Advisory – Multiple IBM Sterling Partner Engagement Manager Vulnerabilities
October 24, 2023
Rewterz
Rewterz Threat Advisory – Multiple WordPress Plugins Vulnerabilities
October 24, 2023

Rewterz Threat Advisory – Multiple IBM Security Verify Governance Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2023-33840 CVSS:4.7

IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2023-33839 CVSS:7.2

IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

CVE-2023-33837 CVSS:4.1

IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission.

CVE-2022-22466 CVSS:6.8

IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

Impact

  • Cross-Site Scripting
  • Information Disclosure
  • Gain Access
  • Information Theft

Indicators Of Compromise

CVE

  • CVE-2023-33840
  • CVE-2023-33839
  • CVE-2023-33837
  • CVE-2022-22466

Affected Vendors

IBM

Affected Products

  • IBM Security Verify Governance 10.0

Remediation

Refer to IBM Security Advisory for patch, upgrade or suggested workaround information.

IBM Security Advisory