Credential Storage Vulnerability in IBM Security Verify Products
CVE-2024-45673
5.5MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 21 February 2025
Summary
IBM Security Verify products, including the Bridge Directory Sync and Gateways for Windows Login and Radius, contain a vulnerability where user credentials are stored in configuration files. This design flaw allows local users to access sensitive credential information, potentially leading to unauthorized access and data breaches. Security best practices suggest that sensitive data should not be stored in easily accessible formats, and remediation steps are recommended to protect user information.
Affected Version(s)
Security Verify Bridge Directory Sync 1.0.1 <= 1.0.12
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved