First published: Fri Nov 29 2024(Updated: )
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Access | <=10.0.0 - 10.0.8 IF1 | |
IBM Security Verify Access | >=10.0.0<=10.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49805 is categorized as a high severity vulnerability due to the presence of hard-coded credentials.
To fix CVE-2024-49805, update your IBM Security Verify Access Appliance to the latest version beyond 10.0.8 to eliminate the use of hard-coded credentials.
CVE-2024-49805 affects IBM Security Verify Access Appliance versions 10.0.0 through 10.0.8.
The hard-coded credentials in CVE-2024-49805 can lead to unauthorized access and potential data breaches.
Currently, no specific workaround has been provided for CVE-2024-49805, and upgrading is strongly recommended.