CVE-2023-35017: IBM Security Verify Governance information
IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques.
Other sources
IBM Security Verify Governance, Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35017?
CVE-2023-35017 is considered a high severity vulnerability due to the potential exposure of user credentials.
How do I fix CVE-2023-35017?
To fix CVE-2023-35017, upgrade to a secure version of IBM Security Verify Governance, Identity Manager that addresses this vulnerability.
What impact does CVE-2023-35017 have on system security?
CVE-2023-35017 can allow attackers to intercept and access user credentials transmitted in clear text over the network.
Which IBM products are affected by CVE-2023-35017?
CVE-2023-35017 affects IBM Security Verify Governance, Identity Manager and its virtual appliance component up to version 10.0.2.
Can CVE-2023-35017 be exploited easily?
Yes, CVE-2023-35017 can be exploited using man-in-the-middle techniques, making it critical to secure communications.