Ibm · Ibm Security Verify Governance Identity Manager · CVE-2023-35018
**Name of the Vulnerable Software and Affected Versions**
IBM Security Verify Governance version 10.0
IBM Security Verify Governance Identity Manager version 10.0
**Description**
The issue is related to improper file validation, allowing a privileged user to upload arbitrary files. Additionally, there is a problem with improper access controls, which could enable a local user to escalate their privileges.
**Recommendations**
For IBM Security Verify Governance version 10.0, consider restricting file upload capabilities until a proper fix is applied.
For IBM Security Verify Governance Identity Manager version 10.0, limit access to sensitive areas of the system to prevent privilege escalation until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.