CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AI Score
Confidence
High
EPSS
Percentile
9.0%
IBM Security Verify Privilege could allow an unauthenticated actor to obtain sensitive information. The issue has been addressed in an update.
CVEID:CVE-2024-31887
**DESCRIPTION:**IBM Security Verify Privilege could allow an unauthenticated actor to obtain sensitive information from the SOAP API.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/287651 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM Security Verify Privilege On-Premises | 11.6.25 |
IBM encourages customers to update their systems promptly.
Upgrade your installation to version 11.6.26 as found here.
Remember to check your system’s audit logs for suspicious activity. Rotate secrets if you suspect or detect signs of suspicious access.
For more information, review these documents:
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | security_verify_privilege_manager | 11.6.26 | cpe:2.3:a:ibm:security_verify_privilege_manager:11.6.26:*:*:*:*:*:*:* |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AI Score
Confidence
High
EPSS
Percentile
9.0%