First published: Wed Apr 10 2024(Updated: )
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor. IBM X-Force ID: 287317.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | <=10.0.X | |
IBM Security Verify Access | >=10.0.0<=10.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31873 is classified as a critical vulnerability due to its use of hard-coded credentials that can be exploited.
To fix CVE-2024-31873, upgrade IBM Security Verify Access Appliance to version 10.0.8 or later.
CVE-2024-31873 affects IBM Security Verify Access Appliance versions 10.0.0 through 10.0.7.
The impact of CVE-2024-31873 includes unauthorized access to systems utilizing hard-coded credentials.
CVE-2024-31873 was reported by IBM X-Force as part of their vulnerability research.