CVE-2023-38370
IBM Security Access Manager (ISAM) vulnerability analysis and mitigation

Overview

IBM Security Access Manager Docker versions 10.0.0.0 through 10.0.7.1, under certain configurations, was found to contain a security vulnerability that could allow network users to install malicious packages. The vulnerability was discovered and reported to IBM by Pierre Barre, and was assigned CVE-2023-38370. The issue was publicly disclosed on June 27, 2024, and received a CVSS v3.1 base score of 7.5 (High) (IBM Advisory).

Technical details

The vulnerability has been assessed with a CVSS v3.1 Vector of CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating that it requires adjacent network access and high attack complexity, but needs no privileges or user interaction. The vulnerability is related to incorrect default permissions (CWE-276) and affects the security configuration of the Docker container (NVD).

Impact

If exploited, this vulnerability could allow an attacker on the network to install malicious packages, potentially leading to high impacts on confidentiality, integrity, and availability of the system. The high CVSS score reflects the significant potential impact of successful exploitation (IBM Advisory).

Mitigation and workarounds

IBM has released version 10.0.8.0 to address this vulnerability. Users are strongly encouraged to update their systems promptly. For Docker Container installations, users should obtain the latest version by running the command 'docker pull icr.io/isva/verify-access:[tag]' where [tag] is the latest published version (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM Security Access Manager (ISAM) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-30998HIGH7.8
  • IBM Security Access Manager (ISAM)IBM Security Access Manager (ISAM)
  • cpe:2.3:a:ibm:security_access_manager
NoNoJun 27, 2024
CVE-2023-38370MEDIUM6.5
  • IBM Security Access Manager (ISAM)IBM Security Access Manager (ISAM)
  • cpe:2.3:a:ibm:security_access_manager
NoNoJun 27, 2024
CVE-2024-35137MEDIUM6.2
  • IBM Security Access Manager (ISAM)IBM Security Access Manager (ISAM)
  • cpe:2.3:a:ibm:security_access_manager
NoNoJun 28, 2024
CVE-2024-35139MEDIUM5.5
  • IBM Security Access Manager (ISAM)IBM Security Access Manager (ISAM)
  • cpe:2.3:a:ibm:security_access_manager
NoNoJun 28, 2024
CVE-2023-38368MEDIUM5.5
  • IBM Security Access Manager (ISAM)IBM Security Access Manager (ISAM)
  • cpe:2.3:a:ibm:security_access_manager
NoNoJun 27, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management