CVE-2023-33838
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Jan 29, 2025
CWE ID 759
Summary
CVE-2023-33838 refers to a vulnerability in IBM Security Verify Governance 10.0.2 Identity Manager. This issue arises due to the system using a one-way cryptographic hash on an input that should not be reversible, specifically passwords, without employing a salt in the hash function. This lack of a salt makes it easier for attackers to gain unauthorized access to user accounts by reverse-engineering the hashed passwords. This weakness poses a significant risk to the security of the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- IBM Corporation