IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default SHA-256 cryptographic algorithm used throughout the Cúram application. IBM X-Force ID: 189156.
The product uses a broken or risky cryptographic algorithm or protocol.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6346575 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/189156 | vdb entry vendor advisory |