Show filters
189 Total Results
Displaying 91-100 of 189
Sort by:
Attacker Value
Unknown

CVE-2022-33161

Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.
Attacker Value
Unknown

CVE-2022-32755

Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.
Attacker Value
Unknown

CVE-2023-33835

Disclosure Date: August 31, 2023 (last updated October 08, 2023)
IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 256015.
Attacker Value
Unknown

CVE-2023-33834

Disclosure Date: August 31, 2023 (last updated October 08, 2023)
IBM Security Verify Information Queue 10.0.4 and 10.0.5 could allow a remote attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-force ID: 256014.
Attacker Value
Unknown

CVE-2023-33833

Disclosure Date: August 31, 2023 (last updated October 08, 2023)
IBM Security Verify Information Queue 10.0.4 and 10.0.5 stores sensitive information in plain clear text which can be read by a local user. IBM X-Force ID: 256013.
Attacker Value
Unknown

CVE-2023-35019

Disclosure Date: July 31, 2023 (last updated October 08, 2023)
IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 257873.
Attacker Value
Unknown

CVE-2023-35016

Disclosure Date: July 31, 2023 (last updated October 08, 2023)
IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257772.
Attacker Value
Unknown

CVE-2023-30433

Disclosure Date: July 19, 2023 (last updated October 08, 2023)
IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 252186.
Attacker Value
Unknown

CVE-2023-25927

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-Force ID: 247635.
Attacker Value
Unknown

CVE-2022-36775

Disclosure Date: February 17, 2023 (last updated November 08, 2023)
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 233576.