First published: Tue Jan 09 2024(Updated: )
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254658.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | <=10.0.0.0 - 10.0.6.1 | |
IBM Security Verify Access | <=10.0.0.0 - 10.0.6.1 | |
IBM Security Verify Access OIDC Provider | >=10.0.0.0<10.0.0.7 | |
IBM Security Verify Access | >=10.0.0.0<10.0.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31003 has a high severity due to the potential for local users to gain root access.
To fix CVE-2023-31003, upgrade to IBM Security Verify Access versions 10.0.0.7 or higher.
CVE-2023-31003 affects IBM Security Verify Access versions 10.0.0.0 through 10.0.6.1.
CVE-2023-31003 requires local access for exploitation, minimizing remote attack potential.
Organizations using affected versions of IBM Security Verify Access are at risk of unauthorized root access.