Credential Storage Vulnerability in IBM Security Verify Products
CVE-2024-45673

5.5MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
21 February 2025

Summary

IBM Security Verify products, including the Bridge Directory Sync and Gateways for Windows Login and Radius, contain a vulnerability where user credentials are stored in configuration files. This design flaw allows local users to access sensitive credential information, potentially leading to unauthorized access and data breaches. Security best practices suggest that sensitive data should not be stored in easily accessible formats, and remediation steps are recommended to protect user information.

Affected Version(s)

Security Verify Bridge Directory Sync 1.0.1 <= 1.0.12

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.