### [CVE-2023-45182](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45182) ![](https://img.shields.io/static/v1?label=Product&message=i%20Access%20Client%20Solutions&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=1.1.2%3C%3D%201.1.4%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-922%20Insecure%20Storage%20of%20Sensitive%20Information&color=brighgreen) ### Description IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265. ### POC #### Reference No PoCs from references. #### Github - https://github.com/DojoSecurity/DojoSecurity - https://github.com/afine-com/CVE-2023-45182 - https://github.com/afine-com/research - https://github.com/nomi-sec/PoC-in-GitHub