Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2021-38859

Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that could be used in further attacks against the system. IBM X-Force ID: 207899.
Attacker Value
Unknown

CVE-2021-29913

Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 207898.
Attacker Value
Unknown

CVE-2021-20581

Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324.
Attacker Value
Unknown

CVE-2022-22384

Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due to hazardous input validation. IBM X-Force ID: 221961.
Attacker Value
Unknown

CVE-2022-22377

Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 221827.
Attacker Value
Unknown

CVE-2020-4609

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and execute arbitrary code on the system or cause the system to crash. IBM X-Force ID: 184917.
Attacker Value
Unknown

CVE-2020-4610

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due to improper integrity checks. IBM X-Force ID: 184919.
Attacker Value
Unknown

CVE-2020-4606

Disclosure Date: January 07, 2021 (last updated February 22, 2025)
IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 184883.
Attacker Value
Unknown

CVE-2020-4607

Disclosure Date: September 28, 2020 (last updated February 22, 2025)
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884.