CVE-2022-22307Incorrect Authorization in IBM Security Guardium

Severity
7.8HIGHNVD
CNA4.4
EPSS
0.0%
top 93.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 15

Description

IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges due to incorrect authorization checks. IBM X-Force ID: 216753.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5ibm/security_guardium11.3, 11.4, 11.5
NVDibm/security_guardium11.3, 11.4, 11.5+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x8rx-wq78-x445: IBM Security Guardium 112023-06-15
CVEList
IBM Security Guardium privilege escalation2023-06-15
CVE-2022-22307 — Incorrect Authorization in IBM | cvebase