PT-2025-1390 · Ibm · Ibm Security Verify Governance
Published
2025-01-29
·
Updated
2025-01-29
·
CVE-2023-33838
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Verify Governance 10.0.2 Identity Manager
Description
The issue arises because the product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but it does not also use a salt as part of the input. This lack of salting in the hashing process could potentially make the hashed passwords more susceptible to certain types of attacks.
Recommendations
For IBM Security Verify Governance 10.0.2 Identity Manager, consider implementing an additional security measure such as salting the input to the one-way cryptographic hash to enhance password security until a patch is available. As a temporary workaround, review and enhance the overall password storage and verification process to minimize potential risks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Security Verify Governance