Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-45670

CVE-2024-45670: IBM SOAR Auth Bypass Vulnerability

CVE-2024-45670 is an authentication bypass flaw in IBM Security SOAR that exploits weak password recovery mechanisms in versions 51.0.1.0 and earlier. This article covers technical details, affected systems, and mitigation.

Published:

CVE-2024-45670 Overview

CVE-2024-45670 affects IBM Security SOAR versions 51.0.1.0 and earlier. The vulnerability stems from a weak password recovery mechanism that allows users to recover or change passwords without knowing the original credential. IBM published the advisory on November 14, 2024, and assigned it a CVSS 3.1 score reflecting high impact across confidentiality, integrity, and availability.

Exploitation requires that an attacker first compromise the target user account. The flaw maps to CWE-640: Weak Password Recovery Mechanism for Forgotten Password. IBM Security SOAR is widely deployed in security operations centers for incident response orchestration.

Critical Impact

Successful exploitation enables an attacker with prior account access to change account passwords through the recovery flow, potentially extending unauthorized access across SOAR workflows and connected security tooling.

Affected Products

  • IBM Security SOAR 51.0.1.0
  • IBM Security SOAR prior to 51.0.1.0
  • IBM Resilient SOAR deployments running affected versions

Discovery Timeline

  • 2024-11-14 - CVE-2024-45670 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-45670

Vulnerability Analysis

The vulnerability resides in the password recovery flow of IBM Security SOAR. The mechanism permits a user to reset or change a password without proving knowledge of the existing password. This design weakness shifts the security boundary entirely onto the upstream authentication layer.

IBM rates the issue with high attack complexity, indicating that exploitation conditions require specific preconditions. The primary precondition is prior compromise of a valid user account through credential theft, session hijacking, or phishing. Once that prerequisite is met, the attacker can leverage the weak recovery flow to lock the legitimate user out and persist access.

The impact extends beyond a single account. SOAR platforms hold privileged automation playbooks, API tokens for security tools, and incident response data. A successful password change through the recovery flow can grant durable control over response automation and integrated security infrastructure.

Root Cause

The root cause is an authentication design flaw classified under [CWE-640]. The recovery mechanism does not require possession of the original password or sufficient secondary verification. This allows the recovery path to bypass standard authentication assurance once an attacker holds any form of session or account access.

Attack Vector

The attack is network accessible and requires no user interaction at the time of exploitation. An attacker who has compromised an account, for example through stolen session cookies or harvested credentials, navigates to the password recovery functionality. The attacker then invokes the recovery flow to set a new password without supplying the original.

This converts a temporary account compromise into persistent control. The high attack complexity rating reflects the need for prior account access rather than any technical difficulty in the recovery flow itself. See the IBM Security Advisory for vendor-confirmed details.

Detection Methods for CVE-2024-45670

Indicators of Compromise

  • Password change events on IBM Security SOAR accounts that occur without a corresponding original-password authentication event in audit logs
  • Recovery-flow invocations originating from IP addresses or geolocations that do not match the user's historical access patterns
  • Successive password changes on the same account within short time windows
  • SOAR API token regeneration or playbook modification immediately following a password change event

Detection Strategies

  • Correlate SOAR authentication logs with password change events to identify recoveries that bypass standard login
  • Baseline normal password reset frequency per user and alert on deviations
  • Monitor for password changes followed by privilege-sensitive actions such as playbook edits or integration credential exports
  • Forward IBM Security SOAR audit logs to a centralized SIEM for cross-source correlation with endpoint and identity telemetry

Monitoring Recommendations

  • Enable verbose audit logging for all account lifecycle events in IBM Security SOAR
  • Alert on password recovery actions performed outside business hours or from new devices
  • Track session reuse and concurrent logins per user account
  • Review administrative and service account activity weekly for unauthorized changes

How to Mitigate CVE-2024-45670

Immediate Actions Required

  • Apply the IBM security update referenced in the IBM Security Advisory for IBM Security SOAR
  • Enforce multi-factor authentication on all SOAR accounts to raise the bar for the prerequisite account compromise
  • Rotate API tokens, integration credentials, and administrative passwords following patch deployment
  • Audit recent password change and recovery events for anomalies prior to the patch window

Patch Information

IBM has released a fixed version of IBM Security SOAR addressing CVE-2024-45670. Administrators should consult the IBM Security Advisory for specific fixed version numbers and upgrade procedures. Apply the update through standard IBM Security SOAR maintenance procedures.

Workarounds

  • Restrict access to the SOAR management interface to trusted network segments using network access controls
  • Require multi-factor authentication at the identity provider layer for all SOAR users
  • Tighten session timeout and require reauthentication for sensitive actions including password change
  • Limit the number of accounts with administrative privileges and review entitlements regularly

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.