CVE-2023-50956
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Dec 18, 2024
CWE ID 256
Summary
CVE-2023-50956 is a vulnerability affecting IBM Storage Defender's Resiliency Service versions 2.0.0 through 2.0.9. This issue grants privileged users unauthorized access to highly sensitive user credentials. The clear-text storage of secret keys is the root cause, enabling attackers to obtain these credentials with ease. This vulnerability poses a significant risk to organizations using IBM Storage Defender and requires immediate attention and patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- IBM Corporation