CVE-2023-35017

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Jan 29, 2025
CWE ID 319

Summary

CVE-2023-35017 is a vulnerability affecting IBM Security Verify Governance 10.0.2 Identity Manager. This issue allows man-in-the-middle attackers to intercept and obtain user credentials in clear text during transmission. The vulnerability poses a significant risk, as clear text transmission of sensitive information can lead to unauthorized access and potential data breaches. IBM strongly recommends implementing encryption methods or other secure transmission protocols to mitigate this risk. Users are urged to update their Identity Manager software to the latest version to protect against this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share