PT-2024-1197 · Ibm · Ibm Security Verify Access Appliance+2

Published

2024-01-10

·

Updated

2024-01-18

·

CVE-2023-31003

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Security Access Manager Container versions 10.0.0.0 through 10.0.6.1 IBM Security Verify Access Appliance versions 10.0.0.0 through 10.0.6.1 IBM Security Verify Access Docker version 10.0.6.1
Description The issue is related to improper access controls, which could allow a local user to obtain root access. This is due to incorrect link resolution before accessing a file, potentially enabling an attacker to elevate their privileges to the root level.
Recommendations For IBM Security Access Manager Container versions 10.0.0.0 through 10.0.6.1, update to a version that includes the fix for this issue. For IBM Security Verify Access Appliance versions 10.0.0.0 through 10.0.6.1, update to a version that includes the fix for this issue. For IBM Security Verify Access Docker version 10.0.6.1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Fix

Link Following

Weakness Enumeration

Related Identifiers

BDU:2024-00556
CVE-2023-31003

Affected Products

Ibm Security Access Manager Container
Ibm Security Verify Access Appliance
Ibm Security Verify Access Docker