Show filters
2,041 Total Results
Displaying 61-70 of 2,041
Sort by:
Attacker Value
Unknown

CVE-2024-45658

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2024-45657

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.
Attacker Value
Unknown

CVE-2024-43187

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Attacker Value
Unknown

CVE-2024-40700

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2024-35138

Disclosure Date: February 04, 2025 (last updated February 23, 2025)
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
0
Attacker Value
Unknown

CVE-2024-45659

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
0
Attacker Value
Unknown

CVE-2025-24507

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
This vulnerability allows appliance compromise at boot time.
0
Attacker Value
Unknown

CVE-2025-24506

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
0
Attacker Value
Unknown

CVE-2025-24505

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.
0
Attacker Value
Unknown

CVE-2025-24504

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An improper input validation the CSRF filter results in unsanitized user input written to the application logs.
0