First published: Tue Jan 09 2024(Updated: )
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254653.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access OIDC Provider | >=10.0.0.0<10.0.0.7 | |
IBM Security Verify Access | >=10.0.0.0<10.0.0.7 | |
IBM Security Verify Access | <=10.0.0.0 - 10.0.6.1 | |
IBM Security Verify Access | <=10.0.0.0 - 10.0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31001 is classified as a moderate severity vulnerability due to the potential exposure of sensitive information.
To mitigate CVE-2023-31001, upgrade to versions of IBM Security Access Manager Container beyond 10.0.6.1.
CVE-2023-31001 affects IBM Security Verify Access Appliance and IBM Security Verify Access Docker versions 10.0.0.0 through 10.0.6.1.
CVE-2023-31001 involves the temporary storage of sensitive information in files, making it accessible to local users.
It is the responsibility of the organization using affected IBM products to address the vulnerabilities associated with CVE-2023-31001.