IBM Security Access Manager Container information disclosure
Description
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Security Access Manager Container 10.0.0.0–10.0.6.1 temporarily stores sensitive data in files accessible to local users, risking information disclosure.
Vulnerability
IBM Security Access Manager Container (IBM Security Verify Access Appliance and Docker) versions 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user [1]. This vulnerability (CVE-2023-31002) is distinct from the similar issue CVE-2023-31001, which also involves temporary storage of sensitive data but with a slightly different attack vector [1]. The affected components include both the Appliance and Docker deployments within the specified version range.
Exploitation
A local user on the system where the container is running can access the temporary files containing sensitive information [1]. The attack requires local access (AV:L) and no special privileges (PR:N), but the attack complexity is high (AC:H) because it depends on precise timing or conditions to access the files while they exist [1]. No user interaction is required beyond having local access to the system.
Impact
Successful exploitation leads to confidentiality impact (high) as the attacker can read sensitive information (e.g., credentials, tokens, or other secrets) that were temporarily stored by the IBM Security Access Manager Container [1]. There is no integrity or availability impact from this specific vulnerability; the attacker only gains read access to the sensitive data.
Mitigation
IBM has addressed this vulnerability in IBM Security Verify Access updates [1]. The fix is included in the Security Bulletin (page/node/7106586) as part of a cumulative update that resolves multiple vulnerabilities. Users should upgrade to a patched version (beyond 10.0.6.1) as detailed in the IBM support page. No workarounds were disclosed in the available reference; applying the latest update is the recommended mitigation.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: 10.0.0.0 - 10.0.6.1
10.0.0.0+ 1 more
- (no CPE)range: 10.0.0.0
- (no CPE)range: 10.0.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.ibm.com/support/pages/node/7106586mitrevendor-advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/254657mitrevdb-entry
News mentions
0No linked articles in our index yet.