First published: Tue Jun 25 2024(Updated: )
IBM Security Access Manager Container could allow a local user to obtain root access due to improper access controls.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | <=10.0.0.0 - 10.0.7.1 | |
Oracle Access Manager | >=10.0.0.0<=10.0.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30997 has been classified as a critical vulnerability due to its potential to allow local users to gain root access.
To remediate CVE-2023-30997, upgrade IBM Security Access Manager Docker to a version higher than 10.0.7.1.
CVE-2023-30997 affects IBM Security Verify Access Docker versions 10.0.0.0 to 10.0.7.1 and IBM Security Access Manager for the same version range.
CVE-2023-30997 requires local access to the affected systems to exploit the improper access controls.
Organizations using the impacted IBM products are responsible for applying patches or upgrades to mitigate CVE-2023-30997.