CVE-2024-45673

IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
References
Link Resource
https://www.ibm.com/support/pages/node/7183801 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:security_verify_bridge_directory_sync:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_radius:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_gateway_for_windows_login:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-02-21 17:15

Updated : 2025-08-27 22:15


NVD link : CVE-2024-45673

Mitre link : CVE-2024-45673

CVE.ORG link : CVE-2024-45673


JSON object : View

Products Affected

ibm

  • security_verify_bridge_directory_sync
  • security_verify_gateway_for_radius
  • security_verify_gateway_for_windows_login

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-260

Password in Configuration File