uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37988 | IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7172200 |
|
Tue, 04 Mar 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-916 |
Wed, 12 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jan 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input. | |
| Title | IBM Security Verify Governance information disclosure | |
| First Time appeared |
Ibm
Ibm security Verify Governance |
|
| Weaknesses | CWE-759 | |
| CPEs | cpe:2.3:a:ibm:security_verify_governance:10.0.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm security Verify Governance |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-02-12T16:46:40.574Z
Reserved: 2023-05-23T00:31:47.071Z
Link: CVE-2023-33838
Updated: 2025-02-12T16:46:14.692Z
Status : Analyzed
Published: 2025-01-29T02:15:26.640
Modified: 2025-03-04T21:58:37.043
Link: CVE-2023-33838
No data.
OpenCVE Enrichment
No data.
EUVD