CVE-2024-45659: IBM Security Verify Access information disclosure
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
Other sources
IBM Security Verify Access Appliance could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45659?
CVE-2024-45659 has been rated as a medium severity vulnerability.
How do I fix CVE-2024-45659?
To mitigate CVE-2024-45659, upgrade IBM Security Verify Access Appliance and Container to version 10.0.9 or later.
What types of attacks can exploit CVE-2024-45659?
CVE-2024-45659 could be exploited by remote attackers to gather sensitive information through detailed technical error messages.
What versions of IBM products are affected by CVE-2024-45659?
CVE-2024-45659 affects IBM Security Verify Access Appliance and Container version 10.0.0 through 10.0.8.
Can CVE-2024-45659 lead to further attacks?
Yes, the sensitive information exposed by CVE-2024-45659 could potentially be used in subsequent attacks against the affected system.