CVE-2023-31004

CWE-3003 documents3 sources
Severity
9.0CRITICAL
EPSS
0.1%
top 67.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 3

Description

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote attacker to gain access to the underlying system using man in the middle techniques. IBM X-Force ID: 254765.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 1.6 | Impact: 6.0

Affected Packages4 packages

CVEListV5ibm/security_verify_access_docker10.0.0.010.0.6.1
NVDibm/security_verify_access_docker10.0.0.010.0.6.1
CVEListV5ibm/security_verify_access_appliance10.0.0.010.0.6.1
NVDibm/security_verify_access10.0.0.010.0.6.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5hg2-mhp5-c2q8: IBM Security Access Manager Container (IBM Security Verify Access Appliance 102024-02-03
CVEList
IBM Security Access Manager Container gain access2024-02-03
CVE-2023-31004 (CRITICAL CVSS 9) | IBM Security Access Manager Contain | cvebase.io