CVE-2023-38370: IBM Security Access Manager Docker information disclosure
IBM Security Access Manager Container, under certain configurations, could allow a user on the network to install malicious packages.
Other sources
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38370?
The severity of CVE-2023-38370 is classified as critical due to the potential for malicious package installation.
How do I fix CVE-2023-38370?
To fix CVE-2023-38370, upgrade your IBM Security Access Manager Docker to a version newer than 10.0.7.1.
Who is affected by CVE-2023-38370?
CVE-2023-38370 affects IBM Security Access Manager Docker versions from 10.0.0.0 to 10.0.7.1.
What configurations are vulnerable in CVE-2023-38370?
CVE-2023-38370 is vulnerable under specific configurations that allow network users to install unverified packages.
What are the implications of CVE-2023-38370?
The implications of CVE-2023-38370 could include unauthorized access and compromise of the system through malicious packages.