Show filters
161 Total Results
Displaying 31-40 of 161
Sort by:
Attacker Value
Unknown
CVE-2022-22456
Disclosure Date: December 22, 2022 (last updated February 24, 2025)
IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225004.
0
Attacker Value
Unknown
CVE-2022-35646
Disclosure Date: December 22, 2022 (last updated February 24, 2025)
IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using man-in-the-middle techniques. IBM X-Force ID: 231096.
0
Attacker Value
Unknown
CVE-2022-22461
Disclosure Date: December 22, 2022 (last updated February 24, 2025)
IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225007.
0
Attacker Value
Unknown
CVE-2022-25628
Disclosure Date: December 16, 2022 (last updated February 24, 2025)
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
0
Attacker Value
Unknown
CVE-2022-25627
Disclosure Date: December 16, 2022 (last updated October 08, 2023)
An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4
0
Attacker Value
Unknown
CVE-2022-25626
Disclosure Date: December 16, 2022 (last updated October 08, 2023)
An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.
0
Attacker Value
Unknown
CVE-2022-36344
Disclosure Date: August 16, 2022 (last updated February 24, 2025)
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of the Windows service if it is placed in a certain path. Affected products are bundled with the following product series: Office and Office Integrated Software, ATOK, Hanako, JUST PDF, Shuriken, Homepage Builder, JUST School, JUST Smile Class, JUST Smile, JUST Frontier, JUST Jump, and Tri-De DetaProtect.
0
Attacker Value
Unknown
CVE-2022-22455
Disclosure Date: August 16, 2022 (last updated October 08, 2023)
IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 224989.
0
Attacker Value
Unknown
CVE-2022-22452
Disclosure Date: July 13, 2022 (last updated February 24, 2025)
IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918.
0
Attacker Value
Unknown
CVE-2022-22460
Disclosure Date: July 13, 2022 (last updated October 07, 2023)
IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013.
0