CVE-2023-38267: IBM Security Access Manager Appliance information disclosure
IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain sensitive configuration information. IBM X-Force ID: 260584.
Other sources
IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 260584.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38267?
CVE-2023-38267 is considered a medium severity vulnerability that allows local users to access sensitive configuration information.
How do I fix CVE-2023-38267?
To address CVE-2023-38267, you should upgrade IBM Security Access Manager Appliance or Docker to version 10.0.6.2 or later.
What versions are affected by CVE-2023-38267?
CVE-2023-38267 affects IBM Security Verify Access versions 10.0.0.0 through 10.0.6.1 and the corresponding Docker version.
Who can exploit CVE-2023-38267?
CVE-2023-38267 can be exploited by local users who have access to the affected IBM Security Verify Access systems.
What sensitive information can be accessed due to CVE-2023-38267?
CVE-2023-38267 may allow unauthorized local users to obtain sensitive configuration data from the affected security appliances.