CVE-2023-38370

Severity
6.5MEDIUM
EPSS
0.0%
top 89.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27

Description

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

CVEListV5ibm/security_access_manager_docker10.0.0.010.0.7.1
NVDibm/security_access_manager10.0.0.010.0.7.1

🔴Vulnerability Details

2
CVEList
IBM Security Access Manager Docker information disclosure2024-06-27
GHSA
GHSA-47wp-r97g-7q4m: IBM Security Access Manager Docker 102024-06-27
CVE-2023-38370 (MEDIUM CVSS 6.5) | IBM Security Access Manager Docker | cvebase.io