Description
IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force ID: 272532.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-51839 | IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force ID: 272532. |
References
History
No history.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-09-16T18:43:12.063Z
Reserved: 2023-11-09T11:31:41.192Z
Link: CVE-2023-47741
Updated: 2024-08-02T21:16:43.677Z
Status : Modified
Published: 2023-12-18T20:15:08.213
Modified: 2024-11-21T08:30:44.820
Link: CVE-2023-47741
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD