PT-2025-15695 · Ibm · Ibm Security Verify Governance

Published

2025-04-09

·

Updated

2025-04-10

·

CVE-2023-33844

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: IBM Security Verify Governance version 10.0.2
Description: The issue allows users to embed arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially leading to credentials disclosure within a trusted session. This is due to a cross-site scripting vulnerability.
Recommendations: For IBM Security Verify Governance version 10.0.2, consider disabling JavaScript execution in the Web UI as a temporary workaround until a patch is available. Restrict access to sensitive areas of the interface to minimize the risk of exploitation. Avoid using the interface for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-33844

Affected Products

Ibm Security Verify Governance