PT-2024-26331 · Ibm · Ibm Security Access Manager
Published
2024-06-28
·
Updated
2024-07-31
·
CVE-2024-35137
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Access Manager Docker versions 10.0.0.0 through 10.0.7.1
Description
The issue allows a local user to possibly elevate their privileges due to sensitive configuration information being exposed.
Recommendations
For versions 10.0.0.0 through 10.0.7.1, consider restricting access to sensitive configuration information to minimize the risk of exploitation. As a temporary workaround, review and secure the configuration to prevent potential privilege elevation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Security Access Manager