ZeroHour

CVE-2023-25681

CVSS 3.1
6.5 medium
EPSS
<1%p45
Published
()
Modified
Description

LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and password. This does not affect local users with MFA configured or remote users authenticating via single sign-on. IBM X-Force ID: 247033.

Vendors
ibm
Products
spectrum virtualize
Weakness
CWE-308
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.