PT-2025-7417 · Ibm · Ibm Security Verify Gateway For Radius+2
Published
2025-02-21
·
Updated
2025-06-18
·
CVE-2024-45673
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Verify Bridge Directory Sync versions 1.0.1 through 1.0.12
IBM Security Verify Gateway for Windows Login versions 1.0.1 through 1.0.10
IBM Security Verify Gateway for Radius versions 1.0.1 through 1.0.11
Description
The issue concerns the storage of user credentials in configuration files, which can be accessed by a local user. This poses a risk as sensitive information can be compromised.
Recommendations
For IBM Security Verify Bridge Directory Sync versions 1.0.1 through 1.0.12, consider restricting access to configuration files to minimize the risk of credential exposure.
For IBM Security Verify Gateway for Windows Login versions 1.0.1 through 1.0.10, restrict access to configuration files to prevent unauthorized access to user credentials.
For IBM Security Verify Gateway for Radius versions 1.0.1 through 1.0.11, limit access to configuration files to reduce the risk of credential compromise.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Verify Bridge Directory Sync
Ibm Security Verify Gateway For Radius
Ibm Security Verify Gateway For Windows Login