CVE-2023-32329: IBM Security Access Manager Container improper file validation
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to improper file validation. IBM X-Force ID: 254972.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32329?
CVE-2023-32329 has been rated as a serious vulnerability due to improper file validation allowing unauthorized file downloads.
How do I fix CVE-2023-32329?
To fix CVE-2023-32329, you should upgrade to IBM Security Access Manager version 10.0.6.2 or later.
What products are affected by CVE-2023-32329?
CVE-2023-32329 affects IBM Security Verify Access Appliance and IBM Security Verify Access Docker versions 10.0.0.0 through 10.0.6.1.
Is there a workaround for CVE-2023-32329?
Currently, IBM recommends applying the latest updates as the primary mitigation approach for CVE-2023-32329.
What could happen if CVE-2023-32329 is exploited?
If exploited, CVE-2023-32329 could allow an attacker to download sensitive files from an incorrect repository.