Show filters
189 Total Results
Displaying 81-90 of 189
Sort by:
Attacker Value
Unknown

CVE-2021-38859

Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that could be used in further attacks against the system. IBM X-Force ID: 207899.
Attacker Value
Unknown

CVE-2021-29913

Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 207898.
Attacker Value
Unknown

CVE-2021-20581

Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324.
Attacker Value
Unknown

CVE-2022-22384

Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due to hazardous input validation. IBM X-Force ID: 221961.
Attacker Value
Unknown

CVE-2022-22377

Disclosure Date: October 17, 2023 (last updated October 19, 2023)
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 221827.
Attacker Value
Unknown

CVE-2023-33836

Disclosure Date: October 16, 2023 (last updated October 20, 2023)
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 256016.
Attacker Value
Unknown

CVE-2023-35018

Disclosure Date: October 16, 2023 (last updated October 20, 2023)
IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.
Attacker Value
Unknown

CVE-2023-35013

Disclosure Date: October 16, 2023 (last updated October 20, 2023)
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769.
Attacker Value
Unknown

CVE-2022-43868

Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM Security Verify Access OIDC Provider could disclose directory information that could aid attackers in further attacks against the system. IBM X-Force ID: 239445.
Attacker Value
Unknown

CVE-2022-43740

Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 238921.