CVE Vulnerabilities

CVE-2024-45647

Unverified Password Change

Published: Jan 20, 2025 | Modified: Jan 29, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Affected Software

NameVendorStart VersionEnd Version
Security_verify_accessIbm10.0.0 (including)10.0.8 (including)
Security_verify_access_dockerIbm10.0.0 (including)10.0.8 (including)

Potential Mitigations

References