CVE-2023-33838 Details
Description
IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
A vulnerability exists in IBM Security Verify Governance 10.0.2 Identity Manager, where a one-way cryptographic hash is applied to inputs like passwords without the use of a salt. This omission can make the hashing process reversible, potentially allowing for the original input to be retrieved.
Users are advised to update to version 10.0.2.0-ISS-ISVG-IGVA-FP0004, available through the IBM Support Fix Central.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7172200 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-759 | Use of a One-Way Hash without a Salt | [email protected] |
| CWE-916 | Use of Password Hash With Insufficient Computational Effort | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm security verify governance | 10.0.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2025 | Initial Analysis | [email protected] |
| Jan 29, 2025 | New CVE Received | [email protected] |