IBM Spectrum Virtualize 8.5 Multifactor Authentication Bypass Vulnerability
CVE-2023-25681
6.5MEDIUM
What is CVE-2023-25681?
A vulnerability exists in IBM Spectrum Virtualize 8.5 where LDAP users, despite being configured for multifactor authentication (MFA), can authenticate to the CIM interface using only their username and password. This security flaw exposes organizations to potential unauthorized access, as it undermines the intended protection MFA offers. Local users who have MFA enabled, as well as remote users authenticating through single sign-on, are not impacted by this issue. Organizations utilizing IBM Spectrum Virtualize should be aware of this vulnerability and take necessary precautions to mitigate risks associated with LDAP configurations.
Affected Version(s)
Spectrum Virtualize 8.5