IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Security_verify_access | Ibm | 10.0.0 (including) | 10.0.8 (including) |
Security_verify_access_docker | Ibm | 10.0.0 (including) | 10.0.8 (including) |