Back

MEDIUM

IBM i information disclosure

Published Dec 18, 2023

Description

IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force ID: 272532.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ibm
Published Dec 18, 2023
Updated Sep 16, 2024
Reserved Nov 9, 2023

CISA Vulnrichment

Updated Sep 16, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner ibm
Published Dec 18, 2023
Updated Sep 16, 2024

GitHub

No data