← Vulnerability feed

Vulnerability record · CVE-2022-33161 · published 14 October 2023

CVE-2022-33161: Ibm security directory integrator missing encryption vulnerability

Ibm · Security Directory Integrator

IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.

5.9 CVSS 3.1 Medium EPSS 0.43% · top 65.4% CWE-311 · Missing encryption
5.9CVSS 3.1 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-33161 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-33162Ibm security directory integrator memory buffer overflow vulnerabilityIBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that re…EPSS 0.43%9.1CVE-2022-32755Ibm security directory server xml injection vulnerabilityIBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could …EPSS 0.71%9.1CVE-2022-33164Ibm security directory server path traversal vulnerabilityIBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted U…EPSS 1.5%8.8CVE-2024-51450Ibm security verify directory os command injection vulnerabilityIBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sendin…EPSS 1.1%8.8CVE-2024-28767Ibm security directory integrator os command injection vulnerabilityIBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary c…EPSS 0.67%8.2CVE-2019-4538Ibm security directory server open redirect vulnerabilityIBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim …EPSS 1.3%7.8CVE-2025-1411Ibm security verify directory execution with unnecessary privileges vulnerabilityIBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecess…EPSS 0.17%7.5CVE-2024-45650Ibm security verify directory vulnerabilityIBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation.EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2022-33161), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.