PT-2025-2718 · Ibm · Ibm Security Verify Access Docker+1

Published

2024-09-03

·

Updated

2025-01-20

·

CVE-2024-45647

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: IBM Security Verify Access versions 10.0.0 through 10.0.8 IBM Security Verify Access Docker versions 10.0.0 through 10.0.8
Description: The issue allows an unverified user to change the password of an expired user without prior knowledge of that password.
Recommendations: For IBM Security Verify Access versions 10.0.0 through 10.0.8, consider disabling the password reset function for expired users until a patch is available. For IBM Security Verify Access Docker versions 10.0.0 through 10.0.8, consider disabling the password reset function for expired users until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-01642
CVE-2024-45647

Affected Products

Ibm Security Verify Access
Ibm Security Verify Access Docker