CVE-2024-45658: IBM Security Verify Access information disclosure
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
Other sources
IBM Security Verify Access Appliance could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45658?
CVE-2024-45658 has been classified with a medium severity level due to the potential exposure of sensitive information.
How do I fix CVE-2024-45658?
To mitigate CVE-2024-45658, upgrade IBM Security Verify Access Appliance and Container to version 10.0.9 or later.
What type of information is exposed by CVE-2024-45658?
CVE-2024-45658 could expose sensitive information through detailed technical error messages.
Who is affected by CVE-2024-45658?
CVE-2024-45658 affects users of IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8.
Can CVE-2024-45658 be exploited remotely?
Yes, CVE-2024-45658 can be exploited by a remote attacker if detailed technical error messages are disclosed.