CVE-2023-33838: IBM Security Verify Governance

Medium severity, CVSS 4.9. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.

Affected products

  • IBM Security Verify Governance: version 10.0.2 only

Published 2025-01-29. Last modified 2026-06-17.