First published: Tue Jan 09 2024(Updated: )
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | >=10.0.0.0<=10.0.6.1 | |
IBM Security Verify Access Docker | <=10.0.0.0 - 10.0.6.1 | |
IBM Security Verify Access Appliance and Container | <=10.0.0.0 - 10.0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32330 is considered a critical security vulnerability due to the potential for remote server control by an attacker.
To fix CVE-2023-32330, upgrade IBM Security Verify Access to a version above 10.0.6.1 as outlined in IBM's security recommendations.
CVE-2023-32330 affects all installations of IBM Security Verify Access versions 10.0.0.0 through 10.0.6.1, including Docker and Appliance versions.
An attacker exploiting CVE-2023-32330 could take control of the server, leading to unauthorized access and manipulation of data.
CVE-2023-32330 was disclosed recently as part of IBM's ongoing security updates and notifications to users.