ID

VAR-202401-2519


CVE

CVE-2023-31003


DESCRIPTION

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254658.

Trust: 1.0

sources: NVD: CVE-2023-31003

AFFECTED PRODUCTS

vendor:ibmmodel:security verify access dockerscope:gteversion:10.0.0.0

Trust: 1.0

vendor:ibmmodel:security verify accessscope:ltversion:10.0.0.7

Trust: 1.0

vendor:ibmmodel:security verify access dockerscope:ltversion:10.0.0.7

Trust: 1.0

vendor:ibmmodel:security verify accessscope:gteversion:10.0.0.0

Trust: 1.0

sources: NVD: CVE-2023-31003

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2023-31003
value: HIGH

Trust: 1.0

psirt@us.ibm.com: CVE-2023-31003
value: HIGH

Trust: 1.0

NVD:
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

psirt@us.ibm.com:
baseSeverity: HIGH
baseScore: 8.4
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.5
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: NVD: CVE-2023-31003 // NVD: CVE-2023-31003

PROBLEMTYPE DATA

problemtype:CWE-59

Trust: 1.0

sources: NVD: CVE-2023-31003

CONFIGURATIONS

sources: NVD: CVE-2023-31003

EXTERNAL IDS

db:NVDid:CVE-2023-31003

Trust: 1.0

sources: NVD: CVE-2023-31003

REFERENCES

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/254658

Trust: 1.0

url:https://www.ibm.com/support/pages/node/7106586

Trust: 1.0

sources: NVD: CVE-2023-31003

SOURCES

db:NVDid:CVE-2023-31003

LAST UPDATE DATE

2024-03-07T22:48:01.098000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2023-31003date:2024-01-18T17:06:42.260

SOURCES RELEASE DATE

db:NVDid:CVE-2023-31003date:2024-01-11T03:15:09.617