CVE-2024-45670: IBM Soar

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.

Affected products

  • IBM Soar: before 51.0.2.0 (fixed in 51.0.2.0)

Published 2024-11-14. Last modified 2026-06-17.