CVE-2024-35138: IBM Security Verify Access cross-site request forgery
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Other sources
IBM Security Verify Access is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35138?
CVE-2024-35138 has been classified as a medium severity vulnerability due to its potential for cross-site request forgery.
How do I fix CVE-2024-35138?
To remediate CVE-2024-35138, upgrade your IBM Security Verify Access Appliance and Container to version 10.0.9 or later.
Which versions are affected by CVE-2024-35138?
CVE-2024-35138 affects IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8.
What kind of attack does CVE-2024-35138 enable?
CVE-2024-35138 allows an attacker to perform cross-site request forgery attacks potentially leading to unauthorized actions.
Is there a workaround for CVE-2024-35138?
Currently, the best mitigation for CVE-2024-35138 is to apply the recommended update to the software in use.