Sensitive Information Stored in Accessible Files
CVE-2023-31002
5.1MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 7 February 2024
Summary
IBM Security Access Manager Container versions 10.0.0.0 to 10.0.6.1 exhibit a vulnerability where sensitive information is stored temporarily in files. This information can be accessed by a local user, potentially leading to unauthorized access to sensitive data. System administrators and security professionals should be aware of this issue and take appropriate measures to mitigate the risk.
Affected Version(s)
Security Verify Access Appliance 10.0.0.0 <= 10.0.6.1
Security Verify Access Docker 10.0.0.0 <= 10.0.6.1
References
CVSS V3.1
Score:
5.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved