Show filters
189 Total Results
Displaying 11-20 of 189
Sort by:
Attacker Value
Unknown

CVE-2024-45659

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
0
Attacker Value
Unknown

CVE-2024-45650

Disclosure Date: January 31, 2025 (last updated February 01, 2025)
IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation.
Attacker Value
Unknown

CVE-2023-33838

Disclosure Date: January 29, 2025 (last updated January 29, 2025)
IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
Attacker Value
Unknown

CVE-2023-35017

Disclosure Date: January 29, 2025 (last updated January 29, 2025)
IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques.
0
Attacker Value
Unknown

CVE-2024-28771

Disclosure Date: January 27, 2025 (last updated January 27, 2025)
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Attacker Value
Unknown

CVE-2024-28770

Disclosure Date: January 27, 2025 (last updated January 27, 2025)
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
Attacker Value
Unknown

CVE-2024-28766

Disclosure Date: January 27, 2025 (last updated January 27, 2025)
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.
Attacker Value
Unknown

CVE-2024-45672

Disclosure Date: January 23, 2025 (last updated January 24, 2025)
IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service.
Attacker Value
Unknown

CVE-2024-45647

Disclosure Date: January 20, 2025 (last updated January 30, 2025)
IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.
Attacker Value
Unknown

CVE-2024-35141

Disclosure Date: December 19, 2024 (last updated January 30, 2025)
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.