IBM i Access Client Solutions information disclosure
CVE-2023-45182
7.4HIGH
Key Information
- Vendor
- IBM
- Status
- i Access Client Solutions
- Vendor
- CVE Published:
- 14 December 2023
Badges
👾 Exploit Exists🔴 Public PoC
Summary
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.
Affected Version(s)
i Access Client Solutions <= 1.1.4
i Access Client Solutions <= 1.1.9.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
- 👾
Exploit exists.
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database1 Proof of Concept(s)