PT-2025-7417 · Ibm · Ibm Security Verify Gateway For Radius+2

Published

2025-02-21

·

Updated

2025-06-18

·

CVE-2024-45673

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Verify Bridge Directory Sync versions 1.0.1 through 1.0.12 IBM Security Verify Gateway for Windows Login versions 1.0.1 through 1.0.10 IBM Security Verify Gateway for Radius versions 1.0.1 through 1.0.11
Description The issue concerns the storage of user credentials in configuration files, which can be accessed by a local user. This poses a risk as sensitive information can be compromised.
Recommendations For IBM Security Verify Bridge Directory Sync versions 1.0.1 through 1.0.12, consider restricting access to configuration files to minimize the risk of credential exposure. For IBM Security Verify Gateway for Windows Login versions 1.0.1 through 1.0.10, restrict access to configuration files to prevent unauthorized access to user credentials. For IBM Security Verify Gateway for Radius versions 1.0.1 through 1.0.11, limit access to configuration files to reduce the risk of credential compromise. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-45673

Affected Products

Ibm Security Verify Bridge Directory Sync
Ibm Security Verify Gateway For Radius
Ibm Security Verify Gateway For Windows Login