IBM Edge Application Manager Incorrect Permission Assignment Vulnerability Allowing Unauthorized Resource Access

Vulnerability

A vulnerability exists in IBM Edge Application Manager version 4.5, where incorrect permission assignments could enable local users to read or modify resources without proper authorization. This issue arises from flawed permission management, potentially leading to unauthorized access or alterations of sensitive resources.

Impact

Exploitation of this vulnerability could result in unauthorized reading or modification of resources, allowing users to access or change information they should not be able to.

Remediation

Users are advised to upgrade to the latest version of IBM Edge Application Manager. The upgrade can be performed using the available Docker images, which will be automatically pulled and deployed from Docker Hub and the IBM Entitled Registry. For detailed upgrade instructions, please refer to the IBM Edge Application Manager 4.5 Upgrade Guide.

Added: Aug 20, 2025, 3:24 PM
Updated: Aug 20, 2025, 3:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
5.0
exploitability
3.8
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.