PT-2022-10872 · Ibm · Ibm Security Verify Access
Published
2022-02-02
·
Updated
2022-07-12
·
CVE-2021-39070
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Security Verify Access versions 10.0.0.0 through 10.0.2.0
Description
The issue allows an attacker to authenticate as any user on the system when the advanced access control authentication service is enabled.
Recommendations
For versions 10.0.0.0 through 10.0.2.0, disable the advanced access control authentication service as a temporary workaround until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Security Verify Access