PT-2024-14032 · Ibm · Ibm Powersc

Published

2024-02-01

·

Updated

2024-02-12

·

CVE-2023-50962

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM PowerSC versions 1.3 through 2.1
Description The issue concerns the lack of implementation of the "HTTP Strict Transport Security" (HSTS) web security policy mechanism in the MFA component. This mechanism is designed to protect against certain types of attacks by ensuring that web browsers only interact with the server over a secure connection. Without HSTS, the system may be more vulnerable to attacks that rely on manipulating or intercepting HTTP connections.
Recommendations For IBM PowerSC versions 1.3 through 2.1, consider implementing the HSTS policy mechanism to enhance the security of the MFA component. As a temporary workaround, restrict access to sensitive resources and ensure that all interactions with the system are conducted over secure connections. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2023-50962

Affected Products

Ibm Powersc