First published: Mon Oct 07 2024(Updated: )
IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Governance - Identity Manager | <=ISVG 10.0.2 | |
IBM Security Verify Governance, Identity Manager | <=ISVG 10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35017 is considered a high severity vulnerability due to the potential exposure of user credentials.
To fix CVE-2023-35017, upgrade to a secure version of IBM Security Verify Governance, Identity Manager that addresses this vulnerability.
CVE-2023-35017 can allow attackers to intercept and access user credentials transmitted in clear text over the network.
CVE-2023-35017 affects IBM Security Verify Governance, Identity Manager and its virtual appliance component up to version 10.0.2.
Yes, CVE-2023-35017 can be exploited using man-in-the-middle techniques, making it critical to secure communications.