CVE-2023-31002: IBM Security Access Manager Container information disclosure
Published Jan 9, 2024
·Updated
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.
Affected Software
3 affected components
IBM Security Verify Access Docker<=10.0.0.0 - 10.0.6.1
IBM Security Verify Access Appliance<=10.0.0.0 - 10.0.6.1
IBM Security Access Manager Container>=10.0.0.0<=10.0.6.1
Remediation
Patch Available
Event History
Jan 9, 2024
CVE Published
via IBM·12:00 AM
Feb 7, 2024
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-31002?
CVE-2023-31002 is classified as a medium severity vulnerability.
2
How do I fix CVE-2023-31002?
To remediate CVE-2023-31002, upgrade IBM Security Access Manager Container to version 10.0.6.2 or later.
3
What types of systems are affected by CVE-2023-31002?
CVE-2023-31002 affects IBM Security Access Manager Container versions 10.0.0.0 through 10.0.6.1.
4
What risk does CVE-2023-31002 pose?
CVE-2023-31002 poses a risk of unauthorized local access to sensitive information temporarily stored in files.
5
Is there a workaround for CVE-2023-31002?
There are no official workarounds for CVE-2023-31002, the recommended action is to apply the latest updates.