Ibm Security Verify Access vulnerabilities
95 known vulnerabilities affecting ibm/security_verify_access.
Total CVEs
95
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH35MEDIUM42LOW6
Vulnerabilities
Page 2 of 5
CVE-2026-1342P3HIGHCVSS 7.9≥ 10.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-04-08
CVE-2026-1342 [HIGH] CWE-829 CVE-2026-1342: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.
nvd
CVE-2024-31872P3HIGHCVSS 8.1≥ 10.0.0, ≤ 10.0.72024-04-10
CVE-2024-31872 [HIGH] CWE-295 CVE-2024-31872: IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.
nvd
CVE-2023-25927P3HIGHCVSS 7.5v10.0.0v10.0.1+5 more2023-05-12
CVE-2023-25927 [HIGH] CWE-20 CVE-2023-25927: IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacke
IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-Force ID: 247635.
nvd
CVE-2023-43016P3HIGHCVSS 7.3≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-43016 [HIGH] CWE-258 CVE-2023-43016: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote user to log into the server due to a user account with an empty password. IBM X-Force ID: 266154.
nvd
CVE-2024-31871P3HIGHCVSS 8.1≥ 10.0.0, ≤ 10.0.72024-04-10
CVE-2024-31871 [HIGH] CWE-295 CVE-2024-31871: IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. IBM X-Force ID: 287306.
nvd
CVE-2021-29665P3HIGHCVSS 7.8v20.072021-06-01
CVE-2021-29665 [HIGH] CWE-787 CVE-2021-29665: IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper
IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with elevated privileges.
nvd
CVE-2026-1343P3HIGHCVSS 7.2≥ 10.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-04-08
CVE-2026-1343 [HIGH] CWE-918 CVE-2026-1343: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy.
nvd
CVE-2021-20576P3HIGHCVSS 7.5v20.072021-06-01
CVE-2021-20576 [HIGH] CVE-2021-20576: IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET
IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.
nvd
CVE-2025-0161P3HIGHCVSS 7.8≥ 10.0.0, ≤ 10.0.0.9v11.0.0+2 more2025-02-20
CVE-2025-0161 [HIGH] CWE-94 CVE-2025-0161: IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user
IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restrictions on code generation.
nvd
CVE-2024-49814P3HIGHCVSS 7.8≥ 10.0.0, ≤ 10.0.32025-02-06
CVE-2024-49814 [HIGH] CWE-250 CVE-2024-49814: IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user
IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges.
nvd
CVE-2023-43017P3HIGHCVSS 7.2≥ 10.0.0.0, ≤ 10.0.6.12024-02-07
CVE-2023-43017 [HIGH] CWE-295 CVE-2023-43017: IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a conf
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.
nvd
CVE-2021-20439P3HIGHCVSS 7.5v10.0.02021-07-15
CVE-2021-20439 [HIGH] CWE-522 CVE-2021-20439: IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials
IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.
nvd
CVE-2023-31005P3HIGHCVSS 7.8≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-31005 [HIGH] CWE-269 CVE-2023-31005: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a local user to escalate their privileges due to an improper security configuration. IBM X-Force ID: 254767.
nvd
CVE-2024-49804P3HIGHCVSS 7.8≥ 10.0.0, ≤ 10.0.82024-11-29
CVE-2024-49804 [HIGH] CWE-250 CVE-2024-49804: IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks.
nvd
CVE-2022-22464P3HIGHCVSS 7.5v10.0.0.0v10.0.1.0+2 more2022-07-08
CVE-2022-22464 [HIGH] CWE-326 CVE-2022-22464: IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than ex
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.
nvd
CVE-2024-43187P3HIGHCVSS 7.5≥ 10.0.0.0, < 10.0.9.02025-02-04
CVE-2024-43187 [HIGH] CWE-319 CVE-2024-43187: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or secu
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
nvd
CVE-2023-32327P3HIGHCVSS 7.1≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-32327 [HIGH] CWE-611 CVE-2023-32327: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume mem
nvd
CVE-2023-31003P3HIGHCVSS 7.8≥ 10.0.0.0, < 10.0.0.72024-01-11
CVE-2023-31003 [HIGH] CWE-59 CVE-2023-31003: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254658.
nvd
CVE-2021-38957P3HIGHCVSS 7.5v10.0.0v10.0.1.0+1 more2022-01-10
CVE-2021-38957 [HIGH] CWE-20 CVE-2021-38957: IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazar
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.
nvd
CVE-2023-31006P3HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-31006 [HIGH] CWE-400 CVE-2023-31006: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to a denial of service attacks on the DSC server. IBM X-Force ID: 254776.
nvd