Ibm Security Verify Access vulnerabilities
118 known vulnerabilities affecting ibm/security_verify_access.
Total CVEs
118
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH49MEDIUM48LOW6
Vulnerabilities
Page 4 of 6
CVE-2022-22465P3HIGHCVSS 7.8v10.0.0.0v10.0.1.0+2 more2022-07-08
CVE-2022-22465 [HIGH] CVE-2022-22465: IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local user to obtain elevated privileges due to improper access permissions. IBM X-Force ID: 225082.
nvd
CVE-2021-38921P3HIGHCVSS 7.5v10.0.0v10.0.1.0+1 more2022-01-10
CVE-2021-38921 [HIGH] CWE-327 CVE-2021-38921: IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithm
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210067.
nvd
CVE-2026-13260P3HIGHCVSS 7.5≥ 10.0.0, ≤ 10.0.9.2 Interim Fix 0012026-09-14
CVE-2026-13260 [HIGH] CWE-770 CVE-2026-13260: IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insuffi
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
nvd
CVE-2026-12358P3HIGHCVSS 7.5≥ 10.0.0, ≤ 10.0.9.2 Interim Fix 0012026-09-15
CVE-2026-12358 [HIGH] CWE-674 CVE-2026-12358: IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insuffi
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
nvd
CVE-2026-11926P3HIGHCVSS 7.5≥ 10.0.0, ≤ 10.0.9.2 Interim Fix 0012026-09-15
CVE-2026-11926 [HIGH] CWE-400 CVE-2026-11926: IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insuffi
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
nvd
CVE-2026-5926P3MEDIUMCVSS 6.5≥ 10.0.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-04-23
CVE-2026-5926 [MEDIUM] CWE-327 CVE-2026-5926: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2021-20537P3MEDIUMCVSS 6.5v10.0.02021-07-15
CVE-2021-20537 [MEDIUM] CWE-798 CVE-2021-20537: IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryp
IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918
nvd
CVE-2026-11927P3MEDIUMCVSS 6.5≥ 10.0.0, ≤ 10.0.9.2 Interim Fix 0012026-09-15
CVE-2026-11927 [MEDIUM] CWE-74 CVE-2026-11927: IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to
IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.
nvd
CVE-2022-43740P3HIGHCVSS 7.5vOIDC Provider2023-10-14
CVE-2022-43740 [HIGH] CWE-400 CVE-2022-43740: IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due
IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 238921.
nvd
CVE-2022-22311P4MEDIUMCVSS 6.5v10.0.0v10.0.1+2 more2022-03-31
CVE-2022-22311 [MEDIUM] CWE-20 CVE-2022-22311: IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensiti
IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.
nvd
CVE-2022-36775P4MEDIUMCVSS 6.5v10.0.0.0v10.0.1.0+4 more2023-02-17
CVE-2022-36775 [MEDIUM] CWE-74 CVE-2022-36775: IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID:
nvd
CVE-2026-7364P4MEDIUMCVSS 6.1≥ 10.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-07-17
CVE-2026-7364 [MEDIUM] CWE-601 CVE-2026-7364: IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit thi
nvd
CVE-2024-35138P4MEDIUMCVSS 6.5≥ 10.0.0, ≤ 10.0.82025-02-04
CVE-2024-35138 [MEDIUM] CWE-352 CVE-2024-35138: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2021-20511P4MEDIUMCVSS 4.9v10.0.02021-07-15
CVE-2021-20511 [MEDIUM] CWE-22 CVE-2021-20511: IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on th
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 198300.
nvd
CVE-2026-2862P4MEDIUMCVSS 5.3≥ 10.0.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-04-01
CVE-2026-2862 [MEDIUM] CWE-444 CVE-2026-2862: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTT
nvd
CVE-2026-1491P4MEDIUMCVSS 5.3≥ 10.0.0.0, ≤ 10.0.9.1≥ 10.0, ≤ 10.0.9.12026-04-01
CVE-2026-1491 [MEDIUM] CWE-444 CVE-2026-1491: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTT
nvd
CVE-2021-29699P4MEDIUMCVSS 6.8v10.0.02021-07-15
CVE-2021-29699 [MEDIUM] CWE-434 CVE-2021-29699: IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary file
IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excuted by an user. IBM X-Force ID: 200600.
nvd
CVE-2026-13276P4MEDIUMCVSS 6.1≥ 10.0.0, ≤ 10.0.9.2 Interim Fix 0012026-09-14
CVE-2026-13276 [MEDIUM] CWE-79 CVE-2026-13276: IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0
IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001.
nvd
CVE-2024-45657P4MEDIUMCVSS 6.7≥ 10.0.0.0, < 10.0.9.02025-02-04
CVE-2024-45657 [MEDIUM] CWE-732 CVE-2024-45657: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privile
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.
nvd
CVE-2024-31883P4MEDIUMCVSS 5.9≥ 10.0.0.0, ≤ 10.0.7.12024-06-27
CVE-2024-31883 [MEDIUM] CWE-703 CVE-2024-31883: IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow an u
IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow an unauthenticated attacker to cause a denial of service due to asymmetric resource consumption. IBM X-Force ID: 287615.
nvd