Description
LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and password. This does not affect local users with MFA configured or remote users authenticating via single sign-on. IBM X-Force ID: 247033.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29596 | LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and password. This does not affect local users with MFA configured or remote users authenticating via single sign-on. IBM X-Force ID: 247033. |
References
History
No history.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-02T11:25:19.391Z
Reserved: 2023-02-11T18:09:03.126Z
Link: CVE-2023-25681
Updated: 2024-08-02T11:25:19.391Z
Status : Awaiting Analysis
Published: 2024-03-05T20:16:00.857
Modified: 2024-11-21T07:49:55.693
Link: CVE-2023-25681
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:11Z
Weaknesses
EUVD