CVE-2024-35137: IBM Security Access Manager Docker information disclosure
IBM Security Access Manager Appliance could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed.
Other sources
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35137?
CVE-2024-35137 is rated as a moderate severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2024-35137?
To fix CVE-2024-35137, it is recommended to apply the latest security patches provided by IBM for the affected versions of the software.
Which IBM products are affected by CVE-2024-35137?
CVE-2024-35137 affects IBM Security Access Manager Docker versions from 10.0.0.0 to 10.0.7.1.
Who can exploit CVE-2024-35137?
CVE-2024-35137 can potentially be exploited by local users who gain access to the sensitive configuration information.
What are the symptoms of an exploit for CVE-2024-35137?
Symptoms of an exploit for CVE-2024-35137 may include unexpected changes in user privileges or unauthorized access to restricted functionalities.