9.8
CVE-2024-45647
- EPSS 0.06%
- Published 20.01.2025 15:15:07
- Last modified 29.01.2025 21:11:50
- Source psirt@us.ibm.com
- Teams watchlist Login
- Open Login
IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.
Data is provided by the National Vulnerability Database (NVD)
Ibm ≫ Security Verify Access Version >= 10.0.0 <= 10.0.8
Ibm ≫ Security Verify Access Docker Version >= 10.0.0 <= 10.0.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.193 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
psirt@us.ibm.com | 5.6 | 2.2 | 3.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-620 Unverified Password Change
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.