CVE-2024-45670

IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.
References
Link Resource
https://www.ibm.com/support/pages/node/7172206 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:soar:*:*:*:*:*:*:*:*

History

16 Nov 2024, 00:24

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:soar:*:*:*:*:*:*:*:*
First Time Ibm
Ibm soar
References () https://www.ibm.com/support/pages/node/7172206 - () https://www.ibm.com/support/pages/node/7172206 - Vendor Advisory
CVSS v2 : unknown
v3 : 5.6
v2 : unknown
v3 : 8.1

15 Nov 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) IBM Security SOAR 51.0.1.0 y versiones anteriores contienen un mecanismo para que los usuarios recuperen o cambien sus contraseñas sin conocer la contraseña original, pero la cuenta de usuario debe verse comprometida antes del mecanismo de recuperación débil.

14 Nov 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-14 12:15

Updated : 2024-11-16 00:24


NVD link : CVE-2024-45670

Mitre link : CVE-2024-45670

CVE.ORG link : CVE-2024-45670


JSON object : View

Products Affected

ibm

  • soar
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password