First published: Tue Jan 09 2024(Updated: )
IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain sensitive configuration information. IBM X-Force ID: 260584.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access OIDC Provider | >=10.0.0.0<10.0.0.7 | |
IBM Security Verify Access | >=10.0.0.0<10.0.0.7 | |
IBM Security Verify Access | <=10.0.0.0 - 10.0.6.1 | |
IBM Security Verify Access | <=10.0.0.0 - 10.0.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38267 is considered a medium severity vulnerability that allows local users to access sensitive configuration information.
To address CVE-2023-38267, you should upgrade IBM Security Access Manager Appliance or Docker to version 10.0.6.2 or later.
CVE-2023-38267 affects IBM Security Verify Access versions 10.0.0.0 through 10.0.6.1 and the corresponding Docker version.
CVE-2023-38267 can be exploited by local users who have access to the affected IBM Security Verify Access systems.
CVE-2023-38267 may allow unauthorized local users to obtain sensitive configuration data from the affected security appliances.