Show filters
4,200 Total Results
Displaying 81-90 of 4,200
Sort by:
Attacker Value
Unknown
CVE-2024-35138
Disclosure Date: February 04, 2025 (last updated February 23, 2025)
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
0
Attacker Value
Unknown
CVE-2024-45659
Disclosure Date: February 04, 2025 (last updated February 05, 2025)
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
0
Attacker Value
Unknown
CVE-2024-45650
Disclosure Date: January 31, 2025 (last updated February 01, 2025)
IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation.
0
Attacker Value
Unknown
CVE-2023-33838
Disclosure Date: January 29, 2025 (last updated January 29, 2025)
IBM Security Verify Governance 10.0.2 Identity Manager
uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
0
Attacker Value
Unknown
CVE-2023-35017
Disclosure Date: January 29, 2025 (last updated January 29, 2025)
IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques.
0
Attacker Value
Unknown
CVE-2022-4975
Disclosure Date: January 27, 2025 (last updated January 28, 2025)
A flaw was found in the Red Hat Advanced Cluster Security (RHACS) portal. When rendering a table view in the portal, for example, on any of the /main/configmanagement/* endpoints, the front-end generates a DOM table-element (id="pdf-table"). This information is then populated with unsanitized data using innerHTML. An attacker with some control over the data rendered can trigger a cross-site scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2024-28771
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
0
Attacker Value
Unknown
CVE-2024-28770
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.
0
Attacker Value
Unknown
CVE-2024-28766
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.
0
Attacker Value
Unknown
CVE-2025-0543
Disclosure Date: January 25, 2025 (last updated January 26, 2025)
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in a globally writable directory resulting in execution by the SetupSVC.exe service in the context of SYSTEM.
0