5.5

CVE-2022-35720

IBM Sterling External Authentication Server information disclosure

IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a local attacker to decrypt sensitive information.  IBM X-Force ID:  231373.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Sterling External Authentication Server Version 6.1.0
   Ibm ≫ Aix Version -
   Ibm ≫ Linux On Ibm Z Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Ibm ≫ Sterling Secure Proxy Version 6.0.3
   Ibm ≫ Aix Version -
   Ibm ≫ Linux On Ibm Z Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
IBM 2.3 0.8 1.4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

https://www.ibm.com/support/pages/node/6890663
Patch
Vendor Advisory
https://www.ibm.com/support/pages/node/6890669
Patch
Vendor Advisory