CVE-2023-33838: IBM Security Verify Governance information disclosure
IBM Security Verify Governance 10.0.2 Identity Manager
uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
Other sources
IBM Security Verify Governance uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33838?
CVE-2023-33838 is rated as a moderate severity vulnerability due to inadequate password hashing mechanisms.
How do I fix CVE-2023-33838?
To mitigate CVE-2023-33838, upgrade to a version of IBM Security Verify Governance that implements proper salting in password hashing.
What versions are affected by CVE-2023-33838?
CVE-2023-33838 affects IBM Security Verify Governance version 10.0.2 and earlier.
What type of vulnerability is CVE-2023-33838?
CVE-2023-33838 is a cryptographic vulnerability related to password hashing without salting.
Is my data at risk due to CVE-2023-33838?
Yes, if you are using IBM Security Verify Governance 10.0.2 or earlier, your data may be at risk due to compromised password security.