First published: Fri Oct 04 2024(Updated: )
IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
=10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33838 is rated as a moderate severity vulnerability due to inadequate password hashing mechanisms.
To mitigate CVE-2023-33838, upgrade to a version of IBM Security Verify Governance that implements proper salting in password hashing.
CVE-2023-33838 affects IBM Security Verify Governance version 10.0.2 and earlier.
CVE-2023-33838 is a cryptographic vulnerability related to password hashing without salting.
Yes, if you are using IBM Security Verify Governance 10.0.2 or earlier, your data may be at risk due to compromised password security.