cbcvebase.

Ibm Security Verify Access vulnerabilities

95 known vulnerabilities affecting ibm/security_verify_access.

Total CVEs
95
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH35MEDIUM42LOW6

Vulnerabilities

Page 2 of 5
CVE-2026-1342P3HIGHCVSS 7.9≥ 10.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-04-08
CVE-2026-1342 [HIGH] CWE-829 CVE-2026-1342: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.
nvd
CVE-2024-31872P3HIGHCVSS 8.1≥ 10.0.0, ≤ 10.0.72024-04-10
CVE-2024-31872 [HIGH] CWE-295 CVE-2024-31872: IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.
nvd
CVE-2023-25927P3HIGHCVSS 7.5v10.0.0v10.0.1+5 more2023-05-12
CVE-2023-25927 [HIGH] CWE-20 CVE-2023-25927: IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacke IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-Force ID: 247635.
nvd
CVE-2023-43016P3HIGHCVSS 7.3≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-43016 [HIGH] CWE-258 CVE-2023-43016: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote user to log into the server due to a user account with an empty password. IBM X-Force ID: 266154.
nvd
CVE-2024-31871P3HIGHCVSS 8.1≥ 10.0.0, ≤ 10.0.72024-04-10
CVE-2024-31871 [HIGH] CWE-295 CVE-2024-31871: IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. IBM X-Force ID: 287306.
nvd
CVE-2021-29665P3HIGHCVSS 7.8v20.072021-06-01
CVE-2021-29665 [HIGH] CWE-787 CVE-2021-29665: IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with elevated privileges.
nvd
CVE-2026-1343P3HIGHCVSS 7.2≥ 10.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-04-08
CVE-2026-1343 [HIGH] CWE-918 CVE-2026-1343: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy.
nvd
CVE-2021-20576P3HIGHCVSS 7.5v20.072021-06-01
CVE-2021-20576 [HIGH] CVE-2021-20576: IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.
nvd
CVE-2025-0161P3HIGHCVSS 7.8≥ 10.0.0, ≤ 10.0.0.9v11.0.0+2 more2025-02-20
CVE-2025-0161 [HIGH] CWE-94 CVE-2025-0161: IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restrictions on code generation.
nvd
CVE-2024-49814P3HIGHCVSS 7.8≥ 10.0.0, ≤ 10.0.32025-02-06
CVE-2024-49814 [HIGH] CWE-250 CVE-2024-49814: IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges.
nvd
CVE-2023-43017P3HIGHCVSS 7.2≥ 10.0.0.0, ≤ 10.0.6.12024-02-07
CVE-2023-43017 [HIGH] CWE-295 CVE-2023-43017: IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a conf IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.
nvd
CVE-2021-20439P3HIGHCVSS 7.5v10.0.02021-07-15
CVE-2021-20439 [HIGH] CWE-522 CVE-2021-20439: IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.
nvd
CVE-2023-31005P3HIGHCVSS 7.8≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-31005 [HIGH] CWE-269 CVE-2023-31005: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a local user to escalate their privileges due to an improper security configuration. IBM X-Force ID: 254767.
nvd
CVE-2024-49804P3HIGHCVSS 7.8≥ 10.0.0, ≤ 10.0.82024-11-29
CVE-2024-49804 [HIGH] CWE-250 CVE-2024-49804: IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks.
nvd
CVE-2022-22464P3HIGHCVSS 7.5v10.0.0.0v10.0.1.0+2 more2022-07-08
CVE-2022-22464 [HIGH] CWE-326 CVE-2022-22464: IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than ex IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.
nvd
CVE-2024-43187P3HIGHCVSS 7.5≥ 10.0.0.0, < 10.0.9.02025-02-04
CVE-2024-43187 [HIGH] CWE-319 CVE-2024-43187: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or secu IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
nvd
CVE-2023-32327P3HIGHCVSS 7.1≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-32327 [HIGH] CWE-611 CVE-2023-32327: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume mem
nvd
CVE-2023-31003P3HIGHCVSS 7.8≥ 10.0.0.0, < 10.0.0.72024-01-11
CVE-2023-31003 [HIGH] CWE-59 CVE-2023-31003: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254658.
nvd
CVE-2021-38957P3HIGHCVSS 7.5v10.0.0v10.0.1.0+1 more2022-01-10
CVE-2021-38957 [HIGH] CWE-20 CVE-2021-38957: IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazar IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.
nvd
CVE-2023-31006P3HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-31006 [HIGH] CWE-400 CVE-2023-31006: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to a denial of service attacks on the DSC server. IBM X-Force ID: 254776.
nvd
Ibm Security Verify Access vulnerabilities | cvebase