CVE-2023-50956: IBM Storage Defender - Resiliency Service information disclosure
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.
Other sources
IBM Storage Defender - Resiliency Service could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50956?
CVE-2023-50956 is classified as a high severity vulnerability due to the potential exposure of sensitive user credentials.
How do I fix CVE-2023-50956?
To fix CVE-2023-50956, upgrade your IBM Storage Defender - Resiliency Service to version 2.0.10 or later.
Who is affected by CVE-2023-50956?
CVE-2023-50956 affects users of IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.9.
What can an attacker do with CVE-2023-50956?
An attacker can exploit CVE-2023-50956 to obtain highly sensitive user credentials stored in clear text.
Is CVE-2023-50956 a remote or local vulnerability?
CVE-2023-50956 is a local vulnerability that requires privileged access to exploit.