Vulnerability Description
IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a local attacker to decrypt sensitive information. IBM X-Force ID: 231373.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Sterling External Authentication Server | 6.1.0 |
| Ibm | Sterling Secure Proxy | 6.0.3 |
| Ibm | Aix | - |
| Ibm | Linux On Ibm Z | - |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/6890663PatchVendor Advisory
- https://www.ibm.com/support/pages/node/6890669PatchVendor Advisory
- https://www.ibm.com/support/pages/node/6890663PatchVendor Advisory
- https://www.ibm.com/support/pages/node/6890669PatchVendor Advisory
FAQ
What is CVE-2022-35720?
CVE-2022-35720 is a vulnerability with a CVSS score of 2.3 (LOW). IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms during installation that could allow a local attacker to decryp...
How severe is CVE-2022-35720?
CVE-2022-35720 has been rated LOW with a CVSS base score of 2.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-35720?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Sterling External Authentication Server, Ibm Sterling Secure Proxy, Ibm Aix, Ibm Linux On Ibm Z, Linux Linux Kernel.