CVE-2023-25681: IBM Spectrum Virtualize
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and password. This does not affect local users with MFA configured or remote users authenticating via single sign-on. IBM X-Force ID: 247033.
Affected products
- IBM Spectrum Virtualize: version 8.5.0.0 only
Published 2024-03-05. Last modified 2026-06-17.