First published: Tue Jun 25 2024(Updated: )
IBM Security Access Manager Appliance could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager Appliance | >=10.0.0.0<=10.0.7.1 | |
IBM Security Verify Access | <=10.0.0.0 - 10.0.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35137 is rated as a moderate severity vulnerability due to the potential for privilege escalation.
To fix CVE-2024-35137, it is recommended to apply the latest security patches provided by IBM for the affected versions of the software.
CVE-2024-35137 affects IBM Security Access Manager Docker versions from 10.0.0.0 to 10.0.7.1.
CVE-2024-35137 can potentially be exploited by local users who gain access to the sensitive configuration information.
Symptoms of an exploit for CVE-2024-35137 may include unexpected changes in user privileges or unauthorized access to restricted functionalities.