CVE-2024-49804: IBM Security Verify Access Appliance privilege escalation
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks.
Other sources
IBM Security Verify Access Appliance could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49804?
CVE-2024-49804 has a medium severity level due to the potential for privilege escalation by non-administrative users.
How do I fix CVE-2024-49804?
To remediate CVE-2024-49804, ensure that all affected versions of IBM Security Verify Access Appliance are updated to a secure version beyond 10.0.8.
Who is affected by CVE-2024-49804?
CVE-2024-49804 affects locales where IBM Security Verify Access Appliance versions 10.0.0 through 10.0.8 are in use.
What causes CVE-2024-49804?
CVE-2024-49804 is caused by unnecessary permissions assigned to tasks that allow locally authenticated non-administrative users to escalate their privileges.
Is there a workaround for CVE-2024-49804?
Currently, the best approach for CVE-2024-49804 is to apply the necessary updates to eliminate the security risk.