cbcvebase.

Ibm Security Verify Access vulnerabilities

118 known vulnerabilities affecting ibm/security_verify_access.

Total CVEs
118
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH49MEDIUM48LOW6

Vulnerabilities

Page 3 of 6
CVE-2021-20576P3HIGHCVSS 7.5v20.072021-06-01
CVE-2021-20576 [HIGH] CVE-2021-20576: IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.
nvd
CVE-2025-0161P3HIGHCVSS 7.8≥ 10.0.0, ≤ 10.0.0.9v11.0.0+2 more2025-02-20
CVE-2025-0161 [HIGH] CWE-94 CVE-2025-0161: IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restrictions on code generation.
nvd
CVE-2024-49814P3HIGHCVSS 7.8≥ 10.0.0, ≤ 10.0.32025-02-06
CVE-2024-49814 [HIGH] CWE-250 CVE-2024-49814: IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges.
nvd
CVE-2026-11932P3HIGHCVSS 7.5≥ 10.0.0, ≤ 10.0.9.2≥ 10.0, ≤ 10.0.9.22026-08-12
CVE-2026-11932 [HIGH] CWE-835 CVE-2026-11932: IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnerable to a denial of service attack.
nvd
CVE-2021-20439P3HIGHCVSS 7.5v10.0.02021-07-15
CVE-2021-20439 [HIGH] CWE-522 CVE-2021-20439: IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.
nvd
CVE-2023-31005P3HIGHCVSS 7.8≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-31005 [HIGH] CWE-269 CVE-2023-31005: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a local user to escalate their privileges due to an improper security configuration. IBM X-Force ID: 254767.
nvd
CVE-2024-49804P3HIGHCVSS 7.8≥ 10.0.0, ≤ 10.0.82024-11-29
CVE-2024-49804 [HIGH] CWE-250 CVE-2024-49804: IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks.
nvd
CVE-2022-22464P3HIGHCVSS 7.5v10.0.0.0v10.0.1.0+2 more2022-07-08
CVE-2022-22464 [HIGH] CWE-326 CVE-2022-22464: IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than ex IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.
nvd
CVE-2024-43187P3HIGHCVSS 7.5≥ 10.0.0.0, < 10.0.9.02025-02-04
CVE-2024-43187 [HIGH] CWE-319 CVE-2024-43187: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or secu IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
nvd
CVE-2023-32327P3HIGHCVSS 7.1≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-32327 [HIGH] CWE-611 CVE-2023-32327: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume mem
nvd
CVE-2023-43017P3HIGHCVSS 7.2≥ 10.0.0.0, ≤ 10.0.6.12024-02-07
CVE-2023-43017 [HIGH] CWE-295 CVE-2023-43017: IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a conf IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.
nvd
CVE-2023-31003P3HIGHCVSS 7.8≥ 10.0.0.0, < 10.0.0.72024-01-11
CVE-2023-31003 [HIGH] CWE-59 CVE-2023-31003: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254658.
nvd
CVE-2021-38957P3HIGHCVSS 7.5v10.0.0v10.0.1.0+1 more2022-01-10
CVE-2021-38957 [HIGH] CWE-20 CVE-2021-38957: IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazar IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.
nvd
CVE-2023-31006P3HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-31006 [HIGH] CWE-400 CVE-2023-31006: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to a denial of service attacks on the DSC server. IBM X-Force ID: 254776.
nvd
CVE-2021-20497P3HIGHCVSS 7.5v10.0.02021-07-15
CVE-2021-20497 [HIGH] CWE-327 CVE-2021-20497: IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that cou IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969
nvd
CVE-2022-32759P3HIGHCVSS 7.5v10.0.02024-07-25
CVE-2022-32759 [HIGH] CWE-613 CVE-2022-32759: IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses ins IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565.
nvd
CVE-2022-22463P3MEDIUMCVSS 6.5v10.0.0.0v10.0.1.0+2 more2022-07-08
CVE-2022-22463 [MEDIUM] CWE-89 CVE-2022-22463: IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQ IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 225079.
nvd
CVE-2026-4938P3MEDIUMCVSS 6.5≥ 10.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-07-17
CVE-2026-4938 [MEDIUM] CWE-863 CVE-2026-4938: IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow an attacker with read-only privileges to make unauthorized modifications and deployments outside of their assigned per
nvd
CVE-2021-29742P3HIGHCVSS 8.0v10.0.02021-07-15
CVE-2021-29742 [HIGH] CVE-2021-29742: IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the syste IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the system. IBM X-Force ID: 201483.
nvd
CVE-2023-30999P3HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-30999 [HIGH] CWE-400 CVE-2023-30999: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 254651.
nvd
Ibm Security Verify Access vulnerabilities | cvebase