CVE-2023-33838
MEDIUMDescription
IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
Is your site exposed to CVE-2023-33838?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | security_verify_governance |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-33838? +
How severe is CVE-2023-33838? +
What products are affected by CVE-2023-33838? +
How do I check if I'm vulnerable to CVE-2023-33838? +
Related Vulnerabilities
A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted …
A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does …
Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and requires a …
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and …
Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer …
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords using unsalted SHA-512 hashes with a …