First published: Tue Jun 25 2024(Updated: )
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 261198.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager Appliance | >=10.0.0.0<=10.0.7.1 | |
IBM Security Verify Access | <=10.0.0.0 - 10.0.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38371 is classified as a significant vulnerability due to the use of weaker than expected cryptographic algorithms.
To mitigate CVE-2023-38371, upgrade IBM Security Access Manager to version 10.0.7.2 or later where stronger cryptographic algorithms are implemented.
CVE-2023-38371 affects IBM Security Verify Access Docker versions 10.0.0.0 through 10.0.7.1 and IBM Security Access Manager within the same version range.
If exploited, CVE-2023-38371 could allow an attacker to decrypt highly sensitive information stored by the affected products.
There are no formal workarounds for CVE-2023-38371, so it is highly recommended to upgrade to a secure version as soon as possible.