IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
The application stores hard-coded credentials (CWE-798) in its code or configuration, which are used for incoming authentication, outgoing communication with external components, or encryption of internal data. Since the values of these credentials are identical across all product installations, anyone who learns their content — for example through software analysis or a leak — can use them directly. The attacker does not need to possess any privileges or require user interaction, and the attack is possible remotely over the network.
An attacker can gain unauthorized access to the device or related components, leading to a breach of data confidentiality and integrity, and in specific scenarios also partial loss of service availability.
Apply patches available from the vendor according to the references: https://www.ibm.com/support/pages/node/7177447. It is recommended to update immediately to a version beyond 10.0.8 and — until the patch is deployed — restrict network access to the device only to trusted hosts using firewall and network segmentation.
IBM Security Verify Access Appliance in versions 10.0.0 to 10.0.8 (inclusive).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LIBM Security Verify Access
APPIbm10.0.0 – 10.0.8
Related vulnerabilities
Privilege escalation do root w IBM Security Verify Access i Verify Identity Access
IBM Security Verify Access — privilege escalation do root przez nadmiarowe uprawnienia
IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)
IBM Security Verify Access — zdalne wykonanie poleceń (command injection)
IBM Security Verify Access — obejście uwierzytelnienia jako dowolny użytkownik