Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Unknown
CVE-2023-33838
Disclosure Date: January 29, 2025 (last updated January 29, 2025)
IBM Security Verify Governance 10.0.2 Identity Manager
uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
0
Attacker Value
Unknown
CVE-2023-35017
Disclosure Date: January 29, 2025 (last updated January 29, 2025)
IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques.
0
Attacker Value
Unknown
CVE-2023-35888
Disclosure Date: March 20, 2024 (last updated January 28, 2025)
IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 258375.
0
Attacker Value
Unknown
CVE-2023-33840
Disclosure Date: October 23, 2023 (last updated October 28, 2023)
IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 256037.
0
Attacker Value
Unknown
CVE-2023-33839
Disclosure Date: October 23, 2023 (last updated October 28, 2023)
IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 256036.
0
Attacker Value
Unknown
CVE-2023-33837
Disclosure Date: October 23, 2023 (last updated October 28, 2023)
IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020.
0
Attacker Value
Unknown
CVE-2022-22466
Disclosure Date: October 23, 2023 (last updated October 28, 2023)
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 225222.
0
Attacker Value
Unknown
CVE-2023-33836
Disclosure Date: October 16, 2023 (last updated October 20, 2023)
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 256016.
0
Attacker Value
Unknown
CVE-2023-35018
Disclosure Date: October 16, 2023 (last updated October 20, 2023)
IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.
0
Attacker Value
Unknown
CVE-2023-35013
Disclosure Date: October 16, 2023 (last updated October 20, 2023)
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769.
0