| Publishing Date | 2025-07-17 |
|---|---|
| Last Update | 2025-07-17 |
| Tracking ID | IBA-2025-01 |
| CVSS Base Score | 8.7 |
| CVSS Vector | CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Red |
Summary
The SecretKey used for automatic logon, which is stored in the JwtIssuerOptions and with which the token is signed, is always the same and can be read from the config file. This means that it was possible to log in to all servers without a password by creating or importing a token from another server.
Affected products
ibaCMC 3.4.5 and lower
How do I know that I'm affected
Check the version number of mentioned applications on your systems.
Solution
Update to ibaCMC 3.5.0. Alternatively, change the SecretKey in your configuration file.
Customer Actions
Please update to ibaCMC 3.5.0 or change the SecretKey in your configuration file.
How to change the secret key in the configuration file.
- Right-click on the ibaCMC Status app.
- Open the Log/Configuration folder.
- Open appsettings.json.
- Go to 'JwtIssuerOptions'.
- Change the SecretKey.
- Restart ibaCMC
Timeline
| 2025-06-13 | Noted by the development team |
| 2025-07-17 | Release of ibaPDA v3.5.0 |
