IBM Security Access Manager Appliance information disclosure
CVE-2023-38267
6.2MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 11 January 2024
Summary
A vulnerability within the IBM Security Access Manager Appliance versions 10.0.0.0 through 10.0.6.1 and the IBM Security Verify Access Docker version 10.0.6.1 has been identified, potentially allowing a local user to elevate their privileges. This scenario arises due to sensitive configuration information being exposed, which could be exploited if accessed by unauthorized users. The potential impact emphasizes the importance of securing configuration settings to mitigate risks associated with privilege escalation.
Affected Version(s)
Security Verify Access Appliance 10.0.0.0 <= 10.0.6.1
Security Verify Access Docker 10.0.0.0 <= 10.0.6.1
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved