Show filters
189 Total Results
Displaying 41-50 of 189
Sort by:
Attacker Value
Unknown
CVE-2024-31874
Disclosure Date: April 10, 2024 (last updated January 29, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow a local user to cause a denial of service. IBM X-Force ID: 287318.
0
Attacker Value
Unknown
CVE-2024-31873
Disclosure Date: April 10, 2024 (last updated January 29, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor. IBM X-Force ID: 287317.
0
Attacker Value
Unknown
CVE-2024-31872
Disclosure Date: April 10, 2024 (last updated January 29, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.
0
Attacker Value
Unknown
CVE-2024-31871
Disclosure Date: April 10, 2024 (last updated January 29, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. IBM X-Force ID: 287306.
0
Attacker Value
Unknown
CVE-2024-28787
Disclosure Date: April 04, 2024 (last updated April 10, 2024)
IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information or cause a denial of service using a specially crafted HTTP request. IBM X-Force ID: 286584.
0
Attacker Value
Unknown
CVE-2024-25027
Disclosure Date: March 31, 2024 (last updated April 03, 2024)
IBM Security Verify Access 10.0.6 could disclose sensitive snapshot information due to missing encryption. IBM X-Force ID: 281607.
0
Attacker Value
Unknown
CVE-2024-0980
Disclosure Date: March 28, 2024 (last updated April 02, 2024)
The Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2022-32756
Disclosure Date: March 22, 2024 (last updated April 02, 2024)
IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 228507.
0
Attacker Value
Unknown
CVE-2022-32754
Disclosure Date: March 22, 2024 (last updated April 02, 2024)
IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 228445.
0
Attacker Value
Unknown
CVE-2022-32753
Disclosure Date: March 22, 2024 (last updated April 02, 2024)
IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228444.
0