cbcvebase.

Ibm Security Verify Access vulnerabilities

95 known vulnerabilities affecting ibm/security_verify_access.

Total CVEs
95
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH35MEDIUM42LOW6

Vulnerabilities

Page 3 of 5
CVE-2021-20497P3HIGHCVSS 7.5v10.0.02021-07-15
CVE-2021-20497 [HIGH] CWE-327 CVE-2021-20497: IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that cou IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969
nvd
CVE-2022-32759P3HIGHCVSS 7.5v10.0.02024-07-25
CVE-2022-32759 [HIGH] CWE-613 CVE-2022-32759: IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses ins IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565.
nvd
CVE-2022-22463P3MEDIUMCVSS 6.5v10.0.0.0v10.0.1.0+2 more2022-07-08
CVE-2022-22463 [MEDIUM] CWE-89 CVE-2022-22463: IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQ IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 225079.
nvd
CVE-2026-4938P3MEDIUMCVSS 6.5≥ 10.0, ≤ 10.0.9.12026-07-17
CVE-2026-4938 [MEDIUM] CWE-863 CVE-2026-4938: IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow an attacker with read-only privileges to make unauthorized modifications and deployments outside of their assigned per
nvd
CVE-2021-29742P3HIGHCVSS 8.0v10.0.02021-07-15
CVE-2021-29742 [HIGH] CVE-2021-29742: IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the syste IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the system. IBM X-Force ID: 201483.
nvd
CVE-2023-30999P3HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-30999 [HIGH] CWE-400 CVE-2023-30999: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 254651.
nvd
CVE-2022-22465P3HIGHCVSS 7.8v10.0.0.0v10.0.1.0+2 more2022-07-08
CVE-2022-22465 [HIGH] CVE-2022-22465: IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local user to obtain elevated privileges due to improper access permissions. IBM X-Force ID: 225082.
nvd
CVE-2021-38921P3HIGHCVSS 7.5v10.0.0v10.0.1.0+1 more2022-01-10
CVE-2021-38921 [HIGH] CWE-327 CVE-2021-38921: IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithm IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210067.
nvd
CVE-2026-5926P3MEDIUMCVSS 6.5≥ 10.0.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-04-23
CVE-2026-5926 [MEDIUM] CWE-327 CVE-2026-5926: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2021-20537P3MEDIUMCVSS 6.5v10.0.02021-07-15
CVE-2021-20537 [MEDIUM] CWE-798 CVE-2021-20537: IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryp IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918
nvd
CVE-2022-43740P3HIGHCVSS 7.5vOIDC Provider2023-10-14
CVE-2022-43740 [HIGH] CWE-400 CVE-2022-43740: IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 238921.
nvd
CVE-2022-22311P4MEDIUMCVSS 6.5v10.0.0v10.0.1+2 more2022-03-31
CVE-2022-22311 [MEDIUM] CWE-20 CVE-2022-22311: IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensiti IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.
nvd
CVE-2022-36775P4MEDIUMCVSS 6.5v10.0.0.0v10.0.1.0+4 more2023-02-17
CVE-2022-36775 [MEDIUM] CWE-74 CVE-2022-36775: IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID:
nvd
CVE-2024-35138P4MEDIUMCVSS 6.5≥ 10.0.0, ≤ 10.0.82025-02-04
CVE-2024-35138 [MEDIUM] CWE-352 CVE-2024-35138: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2021-20511P4MEDIUMCVSS 4.9v10.0.02021-07-15
CVE-2021-20511 [MEDIUM] CWE-22 CVE-2021-20511: IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on th IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 198300.
nvd
CVE-2026-2862P4MEDIUMCVSS 5.3≥ 10.0.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-04-01
CVE-2026-2862 [MEDIUM] CWE-444 CVE-2026-2862: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTT
nvd
CVE-2026-1491P4MEDIUMCVSS 5.3≥ 10.0.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-04-01
CVE-2026-1491 [MEDIUM] CWE-444 CVE-2026-1491: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTT
nvd
CVE-2021-29699P4MEDIUMCVSS 6.8v10.0.02021-07-15
CVE-2021-29699 [MEDIUM] CWE-434 CVE-2021-29699: IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary file IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excuted by an user. IBM X-Force ID: 200600.
nvd
CVE-2025-0163P4MEDIUMCVSS 5.3≥ 10.0.0, < 10.0.9≥ 10.0, ≤ 10.0.82025-06-11
CVE-2025-0163 [MEDIUM] CWE-204 CVE-2025-0163: IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
nvd
CVE-2024-45657P4MEDIUMCVSS 6.7≥ 10.0.0.0, < 10.0.9.02025-02-04
CVE-2024-45657 [MEDIUM] CWE-732 CVE-2024-45657: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privile IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.
nvd
Ibm Security Verify Access vulnerabilities | cvebase