Show filters
189 Total Results
Displaying 151-160 of 189
Sort by:
Attacker Value
Unknown

CVE-2021-20439

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.
Attacker Value
Unknown

CVE-2021-20583

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP GET request by a privileged user due to improper input validation.. IBM X-Force ID: 199396.
Attacker Value
Unknown

CVE-2020-4609

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and execute arbitrary code on the system or cause the system to crash. IBM X-Force ID: 184917.
Attacker Value
Unknown

CVE-2021-29676

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking
Attacker Value
Unknown

CVE-2021-29677

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2020-4610

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due to improper integrity checks. IBM X-Force ID: 184919.
Attacker Value
Unknown

CVE-2021-20585

Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system. IBM X-Force ID: 199398.
Attacker Value
Unknown

CVE-2021-20576

Disclosure Date: May 28, 2021 (last updated November 28, 2024)
IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.
Attacker Value
Unknown

CVE-2021-20575

Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.
Attacker Value
Unknown

CVE-2021-29665

Disclosure Date: May 28, 2021 (last updated February 22, 2025)
IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with elevated privileges.