CVE Vulnerabilities

CVE-2023-32329

Insufficient Verification of Data Authenticity

Published: Feb 03, 2024 | Modified: Feb 07, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to improper file validation. IBM X-Force ID: 254972.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Security_verify_access Ibm 10.0.0.0 (including) 10.0.6.1 (including)
Security_verify_access_docker Ibm 10.0.0.0 (including) 10.0.6.1 (including)

References