#VU85318 Insufficiently protected credentials in IBM i and IBM Db2 Mirror for i - CVE-2023-47741
Published: January 12, 2024
IBM i
IBM Db2 Mirror for i
IBM Corporation
Description
The vulnerability allows a user with physical access to gain access to potentially sensitive information.
The vulnerability exists due to web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious user with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system.