CVE Vulnerabilities

CVE-2024-45647

Unverified Password Change

Published: Jan 20, 2025 | Modified: Jan 29, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Affected Software

Name Vendor Start Version End Version
Security_verify_access Ibm 10.0.0 (including) 10.0.8 (including)
Security_verify_access_docker Ibm 10.0.0 (including) 10.0.8 (including)

Potential Mitigations

References