IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 258375.
References
Link | Resource |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/258375 | Vendor Advisory |
https://www.ibm.com/support/pages/node/7144228 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/258375 | Vendor Advisory |
https://www.ibm.com/support/pages/node/7144228 | Vendor Advisory |
Configurations
History
27 Jan 2025, 15:18
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ibm:security_verify_governance:10.0.2:*:*:*:*:*:*:* | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/258375 - Vendor Advisory | |
References | () https://www.ibm.com/support/pages/node/7144228 - Vendor Advisory | |
First Time |
Ibm
Ibm security Verify Governance |
|
CWE | NVD-CWE-noinfo |
Information
Published : 2024-03-20 14:15
Updated : 2025-01-27 15:18
NVD link : CVE-2023-35888
Mitre link : CVE-2023-35888
CVE.ORG link : CVE-2023-35888
JSON object : View
Products Affected
ibm
- security_verify_governance
CWE