CVE-2023-46175

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Sep 30, 2024
CWE ID 532

Summary

CVE-2023-46175 is a vulnerability affecting IBM Cloud Pak for Multicloud Management versions 2.3 through 2.3 FP8. This issue allows privileged users to access user credentials in plain text from a log file. The log file, which stores user authentication data, is not encrypted, making it an easy target for unauthorized access. This vulnerability exposes sensitive user information and poses a significant risk to the security of the affected system. IBM strongly recommends applying the latest security patch to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share