IBM Security Access Manager Container Under Denial of Service Attack
CVE-2023-31006
6.5MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 3 February 2024
Summary
A denial of service vulnerability has been identified in the IBM Security Access Manager Container, impacting both the IBM Security Verify Access Appliance and its Docker counterpart. These versions are susceptible to attacks that may result in a disruption of services by targeting the DSC server, preventing legitimate users from accessing critical functions. Organizations should prioritize assessing their systems for exposure and explore available patches and mitigation recommendations to safeguard against potential attacks.
Affected Version(s)
Security Verify Access Appliance 10.0.0.0 <= 10.0.6.1
Security Verify Access Docker 10.0.0.0 <= 10.0.6.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved