First published: Tue Jan 09 2024(Updated: )
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to improper file validation. IBM X-Force ID: 254972.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access OIDC Provider | >=10.0.0.0<=10.0.6.1 | |
IBM Security Verify Access | >=10.0.0.0<=10.0.6.1 | |
IBM Security Verify Access | <=10.0.0.0 - 10.0.6.1 | |
IBM Security Verify Access | <=10.0.0.0 - 10.0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32329 has been rated as a serious vulnerability due to improper file validation allowing unauthorized file downloads.
To fix CVE-2023-32329, you should upgrade to IBM Security Access Manager version 10.0.6.2 or later.
CVE-2023-32329 affects IBM Security Verify Access Appliance and IBM Security Verify Access Docker versions 10.0.0.0 through 10.0.6.1.
Currently, IBM recommends applying the latest updates as the primary mitigation approach for CVE-2023-32329.
If exploited, CVE-2023-32329 could allow an attacker to download sensitive files from an incorrect repository.