cve/2023/CVE-2023-45182.md
2024-05-28 08:49:17 +00:00

21 lines
1002 B
Markdown

### [CVE-2023-45182](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45182)
![](https://img.shields.io/static/v1?label=Product&message=i%20Access%20Client%20Solutions&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=1.1.2%3C%3D%201.1.4%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-922%20Insecure%20Storage%20of%20Sensitive%20Information&color=brighgreen)
### Description
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/DojoSecurity/DojoSecurity
- https://github.com/afine-com/CVE-2023-45182
- https://github.com/afine-com/research
- https://github.com/nomi-sec/PoC-in-GitHub