Rewterz Threat Advisory – Multiple IBM Sterling Partner Engagement Manager Vulnerabilities
October 24, 2023Rewterz Threat Advisory – Multiple WordPress Plugins Vulnerabilities
October 24, 2023Rewterz Threat Advisory – Multiple IBM Sterling Partner Engagement Manager Vulnerabilities
October 24, 2023Rewterz Threat Advisory – Multiple WordPress Plugins Vulnerabilities
October 24, 2023Severity
Medium
Analysis Summary
CVE-2023-33840 CVSS:4.7
IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2023-33839 CVSS:7.2
IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
CVE-2023-33837 CVSS:4.1
IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission.
CVE-2022-22466 CVSS:6.8
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Impact
- Cross-Site Scripting
- Information Disclosure
- Gain Access
- Information Theft
Indicators Of Compromise
CVE
- CVE-2023-33840
- CVE-2023-33839
- CVE-2023-33837
- CVE-2022-22466
Affected Vendors
IBM
Affected Products
- IBM Security Verify Governance 10.0
Remediation
Refer to IBM Security Advisory for patch, upgrade or suggested workaround information.