CVE-2023-35013: IBM Security Verify Governance information disclosure
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769.
Other sources
Node.js utile module could allow a remote attacker to obtain sensitive information, caused by an uninitialized buffer allocation issue. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information from uninitialized memory or to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-35013?
CVE-2023-35013 is a vulnerability in IBM Security Verify Governance 10.0 Identity Manager that could allow a local privileged user to obtain sensitive information.
What is the severity of CVE-2023-35013?
The severity of CVE-2023-35013 is considered critical with a severity value of 9.1.
How does CVE-2023-35013 impact IBM Security Verify Governance 10.0 Identity Manager?
CVE-2023-35013 allows a local privileged user to obtain sensitive information from the IBM Security Verify Governance 10.0 Identity Manager.
How can I fix CVE-2023-35013?
To fix CVE-2023-35013, it is recommended to update to version 10.0.2 Fixpack 0 of IBM Security Verify Governance Identity Manager.
Where can I find more information about CVE-2023-35013?
You can find more information about CVE-2023-35013 on the IBM X-Force Exchange website.