Lucene search

K
ibmIBMA533188CC411315B912AD0000B29164D15B00CD8B50C463DB4E123DDCC29160B
HistoryApr 16, 2024 - 8:59 p.m.

Security Bulletin: IBM Security Verify Privilege could allow an unauthenticated actor to obtain sensitive information (CVE-2024-31887)

2024-04-1620:59:52
www.ibm.com
11
ibm security verify privilege
unauthenticated actor
sensitive information
cve-2024-31887
soap api
vulnerability
on-premises
upgrade
audit logs
rotate secrets
mitigations
ibm support pages

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%

Summary

IBM Security Verify Privilege could allow an unauthenticated actor to obtain sensitive information. The issue has been addressed in an update.

Vulnerability Details

CVEID:CVE-2024-31887
**DESCRIPTION:**IBM Security Verify Privilege could allow an unauthenticated actor to obtain sensitive information from the SOAP API.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/287651 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Security Verify Privilege On-Premises 11.6.25

Remediation/Fixes

IBM encourages customers to update their systems promptly.

Upgrade your installation to version 11.6.26 as found here.

Workarounds and Mitigations

Remember to check your system’s audit logs for suspicious activity. Rotate secrets if you suspect or detect signs of suspicious access.

For more information, review these documents:

  1. <https://www.ibm.com/support/pages/node/7148305&gt;
  2. <https://www.ibm.com/support/pages/node/7148309&gt;

Affected configurations

Vulners
Node
ibmsecurity_verify_privilege_managerMatch11.6.26
VendorProductVersionCPE
ibmsecurity_verify_privilege_manager11.6.26cpe:2.3:a:ibm:security_verify_privilege_manager:11.6.26:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%

Related for A533188CC411315B912AD0000B29164D15B00CD8B50C463DB4E123DDCC29160B