Show filters
82 Total Results
Displaying 11-20 of 82
Sort by:
Attacker Value
Unknown
CVE-2024-49806
Disclosure Date: November 29, 2024 (last updated January 30, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
0
Attacker Value
Unknown
CVE-2024-49805
Disclosure Date: November 29, 2024 (last updated January 30, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
0
Attacker Value
Unknown
CVE-2024-49804
Disclosure Date: November 29, 2024 (last updated January 30, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks.
0
Attacker Value
Unknown
CVE-2024-49803
Disclosure Date: November 29, 2024 (last updated January 30, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-35133
Disclosure Date: August 29, 2024 (last updated September 21, 2024)
IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
0
Attacker Value
Unknown
CVE-2024-28772
Disclosure Date: July 25, 2024 (last updated August 03, 2024)
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285645.
0
Attacker Value
Unknown
CVE-2022-32759
Disclosure Date: July 25, 2024 (last updated August 03, 2024)
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565.
0
Attacker Value
Unknown
CVE-2024-31883
Disclosure Date: June 27, 2024 (last updated August 03, 2024)
IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow an unauthenticated attacker to cause a denial of service due to asymmetric resource consumption. IBM X-Force ID: 287615.
0
Attacker Value
Unknown
CVE-2023-30430
Disclosure Date: June 27, 2024 (last updated August 03, 2024)
IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace logs. IBM X-Force ID: 252183.
0