First published: Tue Jun 25 2024(Updated: )
IBM Security Access Manager Container, under certain configurations, could allow a user on the network to install malicious packages.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager Appliance | >=10.0.0.0<=10.0.7.1 | |
IBM Security Verify Access | <=10.0.0.0 - 10.0.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38370 is classified as critical due to the potential for malicious package installation.
To fix CVE-2023-38370, upgrade your IBM Security Access Manager Docker to a version newer than 10.0.7.1.
CVE-2023-38370 affects IBM Security Access Manager Docker versions from 10.0.0.0 to 10.0.7.1.
CVE-2023-38370 is vulnerable under specific configurations that allow network users to install unverified packages.
The implications of CVE-2023-38370 could include unauthorized access and compromise of the system through malicious packages.