CVE-2024-43187: IBM Security Verify Access information disclosure
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Other sources
IBM Security Verify transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43187?
CVE-2024-43187 has been classified as a high severity vulnerability due to the potential exposure of sensitive data in cleartext.
How do I fix CVE-2024-43187?
To mitigate CVE-2024-43187, upgrade IBM Security Verify Access Appliance and Container to a version higher than 10.0.8 which ensures that sensitive data is transmitted securely.
What data is affected by CVE-2024-43187?
CVE-2024-43187 affects sensitive or security-critical data transmitted in cleartext by IBM Security Verify Access Appliance and Container.
Who does CVE-2024-43187 affect?
CVE-2024-43187 affects users of IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8.
Can CVE-2024-43187 be exploited remotely?
Yes, CVE-2024-43187 can be exploited remotely by unauthorized actors through sniffing communication channels.