First published: Fri Nov 29 2024(Updated: )
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | <=10.0.0 - 10.0.8 IF1 | |
IBM Security Verify Access | >=10.0.0<=10.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49804 has a medium severity level due to the potential for privilege escalation by non-administrative users.
To remediate CVE-2024-49804, ensure that all affected versions of IBM Security Verify Access Appliance are updated to a secure version beyond 10.0.8.
CVE-2024-49804 affects locales where IBM Security Verify Access Appliance versions 10.0.0 through 10.0.8 are in use.
CVE-2024-49804 is caused by unnecessary permissions assigned to tasks that allow locally authenticated non-administrative users to escalate their privileges.
Currently, the best approach for CVE-2024-49804 is to apply the necessary updates to eliminate the security risk.