CVE-2024-35139: IBM Security Access Manager Docker information disclosure
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.
Other sources
IBM Security Verify Access could allow a local user to obtain sensitive information from the container due to incorrect default permissions.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35139?
CVE-2024-35139 has a moderate severity as it could allow local users to access sensitive information.
How do I fix CVE-2024-35139?
To fix CVE-2024-35139, ensure that permissions for sensitive files within the IBM Security Access Manager Docker container are correctly configured.
Who is affected by CVE-2024-35139?
CVE-2024-35139 affects users of IBM Security Access Manager Docker versions 10.0.0.0 through 10.0.7.1.
What types of information could be leaked due to CVE-2024-35139?
CVE-2024-35139 could allow local users to obtain sensitive configuration or credential information stored within the container.
Is CVE-2024-35139 exploitable remotely?
CVE-2024-35139 is not remotely exploitable as it requires local access to the affected system.