First published: Wed Dec 18 2024(Updated: )
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Storage Defender Resiliency Service | <=2.0.0 - 2.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50956 is classified as a high severity vulnerability due to the potential exposure of sensitive user credentials.
To fix CVE-2023-50956, upgrade your IBM Storage Defender - Resiliency Service to version 2.0.10 or later.
CVE-2023-50956 affects users of IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.9.
An attacker can exploit CVE-2023-50956 to obtain highly sensitive user credentials stored in clear text.
CVE-2023-50956 is a local vulnerability that requires privileged access to exploit.