CVE Vulnerabilities

CVE-2023-43016

Empty Password in Configuration File

Published: Feb 03, 2024 | Modified: Nov 03, 2025
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote user to log into the server due to a user account with an empty password. IBM X-Force ID: 266154.

Weakness

Using an empty string as a password is insecure.

Affected Software

NameVendorStart VersionEnd Version
Security_verify_accessIbm10.0.0.0 (including)10.0.6.1 (including)
Security_verify_access_dockerIbm10.0.0.0 (including)10.0.6.1 (including)

Potential Mitigations

References