CVE-2024-45670

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
14/11/2024
Last modified:
16/11/2024

Description

IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:soar:*:*:*:*:*:*:*:* 51.0.2.0 (excluding)


References to Advisories, Solutions, and Tools