CVE-2024-31873: IBM Security Verify Access Appliance information disclosure
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor. IBM X-Force ID: 287317.
Other sources
IBM Security Verify Access Appliance contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31873?
CVE-2024-31873 is classified as a critical vulnerability due to its use of hard-coded credentials that can be exploited.
How do I fix CVE-2024-31873?
To fix CVE-2024-31873, upgrade IBM Security Verify Access Appliance to version 10.0.8 or later.
Which versions of IBM Security Verify Access are affected by CVE-2024-31873?
CVE-2024-31873 affects IBM Security Verify Access Appliance versions 10.0.0 through 10.0.7.
What is the impact of CVE-2024-31873?
The impact of CVE-2024-31873 includes unauthorized access to systems utilizing hard-coded credentials.
Who reported CVE-2024-31873?
CVE-2024-31873 was reported by IBM X-Force as part of their vulnerability research.