CVE-2023-31001: IBM Security Access Manager Container information disclosure
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254653.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31001?
CVE-2023-31001 is classified as a moderate severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2023-31001?
To mitigate CVE-2023-31001, upgrade to versions of IBM Security Access Manager Container beyond 10.0.6.1.
What types of software are affected by CVE-2023-31001?
CVE-2023-31001 affects IBM Security Verify Access Appliance and IBM Security Verify Access Docker versions 10.0.0.0 through 10.0.6.1.
What information is temporarily stored due to CVE-2023-31001?
CVE-2023-31001 involves the temporary storage of sensitive information in files, making it accessible to local users.
Who is responsible for addressing CVE-2023-31001?
It is the responsibility of the organization using affected IBM products to address the vulnerabilities associated with CVE-2023-31001.