CVE-2022-22461
published 2022-12-22CVE-2022-22461: IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.40%
32.6th percentile
IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225007.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_verify_governance | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jwmq-hw4p-5v3p: IBM Security Verify Governance, Identity Manager 10
ghsa_unreviewed·2022-12-22
CVE-2022-22461 [HIGH] CWE-327 GHSA-jwmq-hw4p-5v3p: IBM Security Verify Governance, Identity Manager 10
IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225007.
Ivanti
Ivanti Security Advisory: CVE-2025-22461
vendor_ivanti·2025-04-08·CVSS 7.2
CVE-2025-22461 [HIGH] CWE-89 Ivanti Security Advisory: CVE-2025-22461
Ivanti Security Advisory: CVE-2025-22461
SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve code execution.
CVE IDs: CVE-2025-22461
CVSS Base Score: 7.2
Severity: HIGH
CWEs: CWE-89
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-22
Published