PT-2023-8374 · Ibm · Ibm Security Verify Governance

Published

2023-10-23

·

Updated

2024-09-19

·

CVE-2023-33837

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Verify Governance version 10.0
Description The issue is caused by the lack of encryption for sensitive data. This could allow a remote attacker to disclose protected information.
Recommendations For IBM Security Verify Governance version 10.0, consider implementing encryption for sensitive or critical information before storage or transmission as a temporary workaround until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

BDU:2024-00570
CVE-2023-33837

Affected Products

Ibm Security Verify Governance