CVE Vulnerabilities

CVE-2024-45673

Password in Configuration File

Published: Feb 21, 2025 | Modified: Aug 27, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.

Weakness

The product stores a password in a configuration file that might be accessible to actors who do not know the password.

Affected Software

NameVendorStart VersionEnd Version
Security_verify_bridge_directory_syncIbm1.0.1 (including)1.0.12 (including)
Security_verify_gateway_for_radiusIbm1.0.1 (including)1.0.11 (including)
Security_verify_gateway_for_windows_loginIbm1.0.1 (including)1.0.10 (including)

Potential Mitigations

References