Show filters
189 Total Results
Displaying 61-70 of 189
Sort by:
Attacker Value
Unknown
CVE-2023-31005
Disclosure Date: February 03, 2024 (last updated February 08, 2024)
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a local user to escalate their privileges due to an improper security configuration. IBM X-Force ID: 254767.
0
Attacker Value
Unknown
CVE-2023-31004
Disclosure Date: February 03, 2024 (last updated February 08, 2024)
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote attacker to gain access to the underlying system using man in the middle techniques. IBM X-Force ID: 254765.
0
Attacker Value
Unknown
CVE-2023-30999
Disclosure Date: February 03, 2024 (last updated February 07, 2024)
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 254651.
0
Attacker Value
Unknown
CVE-2023-38267
Disclosure Date: January 11, 2024 (last updated May 24, 2024)
IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 260584.
0
Attacker Value
Unknown
CVE-2023-31003
Disclosure Date: January 11, 2024 (last updated January 19, 2024)
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254658.
0
Attacker Value
Unknown
CVE-2023-31001
Disclosure Date: January 11, 2024 (last updated January 19, 2024)
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254653.
0
Attacker Value
Unknown
CVE-2023-52137
Disclosure Date: December 29, 2023 (last updated January 11, 2024)
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. The [`verify-changed-files`](https://github.com/tj-actions/verify-changed-files) workflow returns the list of files changed within a workflow execution. This could potentially allow filenames that contain special characters such as `;` which can be used by an attacker to take over the [GitHub Runner](https://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runners) if the output value is used in a raw fashion (thus being directly replaced before execution) inside a `run` block. By running custom commands, an attacker may be able to steal secrets such as `GITHUB_TOKEN` if triggered on other events than `pull_request`.
This has been patched in versions [17](https://github.com/tj-actions/verify-changed-files/releases/tag/v17) and [17.0.0]…
0
Attacker Value
Unknown
CVE-2023-36688
Disclosure Date: November 09, 2023 (last updated November 16, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Mann Simple Site Verify plugin <= 1.0.7 versions.
0
Attacker Value
Unknown
CVE-2023-33840
Disclosure Date: October 23, 2023 (last updated October 28, 2023)
IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 256037.
0
Attacker Value
Unknown
CVE-2023-33839
Disclosure Date: October 23, 2023 (last updated October 28, 2023)
IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 256036.
0