Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-19023
HistoryApr 15, 2024 - 12:00 a.m.

IBM Security verify Access Appliance Security Vulnerability

2024-04-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
ibm
security
verify access
appliance
vulnerability
certificate validation
man-in-the-middle
attack
open source
scripts
risk-based access
single sign-on
identity federation
authentication
iot
cloud technologies.

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%

IBM Security Verify Access (ISAM) is a service from International Business Machines (IBM) that improves user access security. The service enables secure and simple access to platforms such as web, mobile, IoT and cloud technologies through the use of risk-based access, single sign-on, integrated access management controls, identity federation, and mobile multi-factor authentication. An unspecified vulnerability exists in the IBM Security verify Access Appliance that stems from a lack of certificate validation and can be exploited by an attacker to conduct a man-in-the-middle attack when deploying open source scripts.

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%

Related for CNVD-2024-19023