MEDIUM
IBM Security Verify Bridge information disclosure
Published Feb 21, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.14%
Description
IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
Affected products
-
Affected
- ≥ 1.0.1, ≤ 1.0.12
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| IBM | Security Verify Bridge Directory Sync | unaffected | Affected
|
AND
OR
- ≥ 1.0.1 · ≤ 1.0.12
- ≥ 1.0.1 · ≤ 1.0.11
- ≥ 1.0.1 · ≤ 1.0.10
Running on/with
OR
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-53876 Advisory
- https://www.ibm.com/support/pages/node/7183801 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-53876 | Advisory | |
| https://www.ibm.com/support/pages/node/7183801 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Feb 21, 2025
Updated Aug 27, 2025
Reserved Sep 3, 2024
Link CVE-2024-45673
CISA Vulnrichment
Updated Feb 21, 2025
Red Hat
No data
GitHub
No data