#VU95286 Incorrect default permissions in Security Verify Access Docker - CVE-2023-38370


Vulnerability identifier: #VU95286

Vulnerability risk: Low

CVSSv4.0: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2023-38370

CWE-ID: CWE-276

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Security Verify Access Docker
Other software / Other software solutions

Vendor: IBM Corporation

Description

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to incorrect default permissions for files and folders that are set by the application. A remote user with access to the system can view contents of files and directories or install malicious packages.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Security Verify Access Docker : before 10.0.8


External links
https://www.ibm.com/support/pages/node/7158790
https://exchange.xforce.ibmcloud.com/vulnerabilities/261197


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability