First published: Thu Feb 20 2025(Updated: )
IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Bridge Directory Sync | <=1.0.1 - 1.0.12 | |
IBM Security Verify Gateway | <=1.0.1 - 1.0.10 | |
IBM Security Verify Gateway | <=1.0.1 - 1.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-45673 is considered high due to the exposure of sensitive user credentials.
To fix CVE-2024-45673, update to the latest version of the affected IBM products where user credentials are not stored in readable configuration files.
CVE-2024-45673 affects IBM Security Verify Bridge Directory Sync versions 1.0.1 to 1.0.12, IBM Security Verify Gateway for Windows Login versions 1.0.1 to 1.0.10, and IBM Security Verify Gateway for Radius versions 1.0.1 to 1.0.11.
CVE-2024-45673 exposes user credentials stored in configuration files that can be accessed by local users.
Yes, CVE-2024-45673 poses a risk of privilege escalation as local users can access sensitive credentials.