CVE Vulnerabilities

CVE-2023-32338

Insufficiently Protected Credentials

Published: Sep 05, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Sterling Secure Proxy and IBM Sterling External Authentication Server 6.0.3 and 6.1.0 stores user credentials in plain clear text which can be read by a local user with container access. IBM X-Force ID: 255585.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Sterling_external_authentication_serverIbm6.0.3.0 (including)6.0.3.0 (including)
Sterling_external_authentication_serverIbm6.1.0 (including)6.1.0 (including)
Sterling_secure_proxyIbm6.0.3 (including)6.0.3 (including)
Sterling_secure_proxyIbm6.1.0 (including)6.1.0 (including)

Potential Mitigations

References