NA

CVE-2023-45182

Published: 14/12/2023 Updated: 18/12/2023
CVSS v3 Base Score: 6.5 | Impact Score: 4 | Exploitability Score: 2
VMScore: 0

Vulnerability Summary

IBM i Access Client Solutions 1.1.2 up to and including 1.1.4 and 1.1.4.3 up to and including 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm i access client solutions

Github Repositories

IBM i Access Client Solutions < 1.1.9.4 - Weak password encryption

CVE-2023-45182 IBM i Access Client Solutions &lt; 1194 - Weak password encryption Timeline Vulnerability reported to vendor: 22092023 New fixed 1194 version released: 08122023 Public disclosure: 15122023 Description IBM i Access Client Solutions for storing user passwords uses AES algorith however 16 bytes encryption key is the combination of static string (Th