PT-2024-1196 · Ibm · Ibm Security Verify Access Appliance+1

Published

2024-01-10

·

Updated

2024-05-24

·

CVE-2023-38267

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Verify Access Appliance versions 10.0.0.0 through 10.0.6.1 IBM Security Verify Access Docker version 10.0.6.1
Description The issue is caused by the lack of encryption of protected data in the IBM Security Verify Access Docker environment. This could allow an attacker to disclose sensitive information. A local user may possibly elevate their privileges due to sensitive configuration information being exposed.
Recommendations For IBM Security Verify Access Appliance versions 10.0.0.0 through 10.0.6.1, consider restricting access to sensitive configuration information until a patch is available. For IBM Security Verify Access Docker version 10.0.6.1, restrict access to sensitive configuration information until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

BDU:2024-00555
CVE-2023-38267

Affected Products

Ibm Security Verify Access Appliance
Ibm Security Verify Access Docker