IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
History

Thu, 19 Jun 2025 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Ibm
Ibm security Verify Bridge Directory Sync
Ibm security Verify Gateway For Radius
Ibm security Verify Gateway For Windows Login
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:ibm:security_verify_bridge_directory_sync:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_radius:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_windows_login:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Bridge Directory Sync
Ibm security Verify Gateway For Radius
Ibm security Verify Gateway For Windows Login
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 21 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Feb 2025 17:00:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
Title IBM Security Verify Bridge information disclosure
Weaknesses CWE-260
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-02-21T16:45:51.122Z

Updated: 2025-02-21T17:12:02.830Z

Reserved: 2024-09-03T13:50:43.964Z

Link: CVE-2024-45673

cve-icon Vulnrichment

Updated: 2025-02-21T17:11:55.301Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-21T17:15:12.900

Modified: 2025-06-18T23:36:20.167

Link: CVE-2024-45673

cve-icon Redhat

No data.