To debug the IBM Verify Gateway (IVG) PAM components, customers can add βtrace-fileβ parameters in the PAM configuration so that .log files are written to the /tmp directory. These debug logs potentially contain sensitive information, and yet they default to world readable. They should have stricter access permissions. As of v1.0.1 of IVG for AIX PAM, and v1.0.2 of IVG for Linux PAM, the logs are no longer world readable.
CVEID:CVE-2020-4405
**DESCRIPTION:**IBM Verify Gateway (IVG) could disclose potentially sensitive information to an authenticated user due to world readable log files.
CVSS Base score: 3.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/179484 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM Verify Gateway (IVG) | PAM 1.0.0, 1.0.1 |
Log in to IBM X-Force Exchange / App Exchange and download and install the latest IBM Security Verify Gateway (renamed from IBM Verify Gateway) PAM components. Specifically:
Use the chmod command to restrict access to PAMβs βtrace-fileβ logs in the /tmp directory.