CVE-2024-45670

MEDIUM

IBM Soar < 51.0.2.0 - Password Reset Weakness

Title source: rule
STIX 2.1

Description

IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.

Scores

CVSS v3 5.6
EPSS 0.0005
EPSS Percentile 14.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-640
Status published
Products (1)
ibm/soar < 51.0.2.0
Published Nov 14, 2024
Tracked Since Feb 18, 2026