CVE-2024-45670: IBM Security SOAR weak password recovery mechanism
IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.
Other sources
IBM Security SOAR contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45670?
CVE-2024-45670 is considered a moderate severity vulnerability due to its potential for allowing unauthorized password recovery.
How do I fix CVE-2024-45670?
To resolve CVE-2024-45670, upgrade your IBM Security SOAR to version 51.0.2.0 or later.
What are the risks associated with CVE-2024-45670?
The risks of CVE-2024-45670 include unauthorized access if a user account is compromised through weak password recovery mechanisms.
What software versions are affected by CVE-2024-45670?
CVE-2024-45670 affects IBM Security SOAR versions 51.0.1.0 and earlier.
Is there a mitigation for CVE-2024-45670?
The primary mitigation for CVE-2024-45670 is to avoid using the vulnerable versions and ensure that the software is updated.