CVE-2023-45182: IBM i Access Client Solutions information disclosure
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.
Other sources
IBM i Access Client Solutions is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45182?
The severity of CVE-2023-45182 is classified as high due to the potential for a local attacker to decode encrypted passwords.
How do I fix CVE-2023-45182?
To fix CVE-2023-45182, upgrade IBM i Access Client Solutions to version 1.1.9.4 or later.
What versions of IBM i Access Client Solutions are affected by CVE-2023-45182?
CVE-2023-45182 affects versions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 of IBM i Access Client Solutions.
What could an attacker do with the vulnerability CVE-2023-45182?
An attacker exploiting CVE-2023-45182 could potentially decode encrypted passwords to gain unauthorized access to other system resources.
Is there a known exploit for CVE-2023-45182?
As of now, there are no specific public exploits reported for CVE-2023-45182, but the vulnerability's existence poses a significant security risk.