CVE-2023-30997: IBM Security Access Manager Docker privilege escalation
IBM Security Access Manager Container could allow a local user to obtain root access due to improper access controls.
Other sources
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254638.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30997?
CVE-2023-30997 has been classified as a critical vulnerability due to its potential to allow local users to gain root access.
How do I fix CVE-2023-30997?
To remediate CVE-2023-30997, upgrade IBM Security Access Manager Docker to a version higher than 10.0.7.1.
What products are affected by CVE-2023-30997?
CVE-2023-30997 affects IBM Security Verify Access Docker versions 10.0.0.0 to 10.0.7.1 and IBM Security Access Manager for the same version range.
Can CVE-2023-30997 be exploited remotely?
CVE-2023-30997 requires local access to the affected systems to exploit the improper access controls.
Who is responsible for addressing CVE-2023-30997?
Organizations using the impacted IBM products are responsible for applying patches or upgrades to mitigate CVE-2023-30997.