CVE-2022-22464
published 2022-07-08CVE-2022-22464: IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.64%
46.5th percentile
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_verify_access | — | — |
| ibm | security_verify_access | — | — |
| ibm | security_verify_access | — | — |
| ibm | security_verify_access | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cj7w-9337-9j7m: IBM Security Access Manager Appliance 10
ghsa_unreviewed·2022-07-09
CVE-2022-22464 [HIGH] CWE-326 GHSA-cj7w-9337-9j7m: IBM Security Access Manager Appliance 10
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.
Ivanti
Ivanti Security Advisory: CVE-2025-22464
vendor_ivanti·2025-04-08·CVSS 6.1
CVE-2025-22464 [MEDIUM] CWE-822 Ivanti Security Advisory: CVE-2025-22464
Ivanti Security Advisory: CVE-2025-22464
An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition.
CVE IDs: CVE-2025-22464
CVSS Base Score: 6.1
Severity: MEDIUM
CWEs: CWE-822
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-08
Published