CVE-2023-25681: IBM Spectrum Virtualize security bypass
LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and password. This does not affect local users with MFA configured or remote users authenticating via single sign-on. IBM X-Force ID: 247033.
Other sources
LDAP users on IBM Spectrum Virtualize which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and password. This does not affect local users with MFA configured or remote users authenticating via single sign-on.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25681?
CVE-2023-25681 is classified as a medium severity vulnerability.
How do I fix CVE-2023-25681?
To fix CVE-2023-25681, ensure that LDAP users are configured to use multifactor authentication for all authentication methods.
Who is affected by CVE-2023-25681?
CVE-2023-25681 affects LDAP users on IBM Spectrum Virtualize 8.5 who require multifactor authentication.
Does CVE-2023-25681 affect local users with MFA?
No, CVE-2023-25681 does not affect local users with MFA configured.
What authentication methods are affected by CVE-2023-25681?
CVE-2023-25681 allows LDAP users to authenticate to the CIM interface using only username and password, bypassing MFA.