Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2020-4405
Disclosure Date: July 23, 2020 (last updated February 21, 2025)
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due to world readable log files. IBM X-Force ID: 179484.
0
Attacker Value
Unknown
CVE-2020-4371
Disclosure Date: July 21, 2020 (last updated February 21, 2025)
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains sensitive information in leftover debug code that could be used aid a local user in further attacks against the system. IBM X-Force ID: 179008.
0
Attacker Value
Unknown
CVE-2020-4397
Disclosure Date: July 21, 2020 (last updated February 21, 2025)
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 179428.
0
Attacker Value
Unknown
CVE-2020-4400
Disclosure Date: July 21, 2020 (last updated February 21, 2025)
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478.
0
Attacker Value
Unknown
CVE-2020-4372
Disclosure Date: July 21, 2020 (last updated February 21, 2025)
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009
0
Attacker Value
Unknown
CVE-2020-4369
Disclosure Date: July 21, 2020 (last updated February 21, 2025)
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a user. IBM X-Force ID: 179004.
0
Attacker Value
Unknown
CVE-2020-4385
Disclosure Date: July 21, 2020 (last updated February 21, 2025)
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 179266.
0
Attacker Value
Unknown
CVE-2020-4399
Disclosure Date: July 21, 2020 (last updated November 28, 2024)
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could allow an authenticated user to send malformed requests to cause a denial of service against the server. IBM X-Force ID: 179476.
0