Skip to main navigation Skip to main content Skip to page footer

The same symmetric key is used for signing authentication tokens.

Security Advisories IBA-2025-01

Green background with a circular digital interface design.
Publishing Date 2025-07-17
Last Update 2025-07-17
Tracking IDIBA-2025-01
CVSS Base Score8.7
CVSS Vector CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Red

Summary

The SecretKey used for automatic logon, which is stored in the JwtIssuerOptions and with which the token is signed, is always the same and can be read from the config file. This means that it was possible to log in to all servers without a password by creating or importing a token from another server.

Affected products

ibaCMC 3.4.5 and lower

How do I know that I'm affected

Check the version number of mentioned applications on your systems.

Solution

Update to ibaCMC 3.5.0. Alternatively, change the SecretKey in your configuration file.

Customer Actions

Please update to ibaCMC 3.5.0 or change the SecretKey in your configuration file.

How to change the secret key in the configuration file.

  • Right-click on the ibaCMC Status app.
  • Open the Log/Configuration folder.
  • Open appsettings.json.
  • Go to 'JwtIssuerOptions'.
  • Change the SecretKey.
  • Restart ibaCMC

Timeline

2025-06-13Noted by the development team
2025-07-17Release of ibaPDA v3.5.0
Back to List View

What would you like to do today?

By choosing a country, my request will be forwarded to the country branch of iba AG responsible for sales and support.Privacy Policy