Ibm Security Verify Access Appliance vulnerabilities
30 known vulnerabilities affecting ibm/security_verify_access_appliance.
Total CVEs
30
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH15MEDIUM10
Vulnerabilities
Page 2 of 2
CVE-2024-35138P4MEDIUMCVSS 6.5≥ 10.0.0, ≤ 10.0.82025-02-04
CVE-2024-35138 [MEDIUM] CWE-352 CVE-2024-35138: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
nvd
CVE-2024-45657P4MEDIUMCVSS 6.7≥ 10.0.0, ≤ 10.0.82025-02-04
CVE-2024-45657 [MEDIUM] CWE-732 CVE-2024-45657: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privile
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.
nvd
CVE-2024-40700P4MEDIUMCVSS 6.1≥ 10.0.0, ≤ 10.0.82025-02-04
CVE-2024-40700 [MEDIUM] CWE-79 CVE-2024-40700: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-38267P4MEDIUMCVSS 5.5≥ 10.0.0.0, ≤ 10.0.6.12024-01-11
CVE-2023-38267 [MEDIUM] CWE-311 CVE-2023-38267: IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.
IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 260584.
nvd
CVE-2023-31002P4MEDIUMCVSS 5.5≥ 10.0.0.0, ≤ 10.0.6.12024-02-07
CVE-2023-31002 [MEDIUM] CWE-312 CVE-2023-31002: IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive informa
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.
nvd
CVE-2023-31001P4MEDIUMCVSS 5.5≥ 10.0.0.0, ≤ 10.0.6.12024-01-11
CVE-2023-31001 [MEDIUM] CWE-257 CVE-2023-31001: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254653.
nvd
CVE-2023-32329P4MEDIUMCVSS 5.5≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-32329 [MEDIUM] CWE-345 CVE-2023-32329: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to improper file validation. IBM X-Force ID: 254972.
nvd
CVE-2024-45658P4MEDIUMCVSS 5.3≥ 10.0.0, ≤ 10.0.82025-02-04
CVE-2024-45658 [MEDIUM] CWE-209 CVE-2024-45658: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attack
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
nvd
CVE-2024-45659P4MEDIUMCVSS 5.3≥ 10.0.0, ≤ 10.0.82025-02-04
CVE-2024-45659 [MEDIUM] CWE-209 CVE-2024-45659: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attack
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
nvd
CVE-2024-31874P4MEDIUMCVSS 5.5≥ 10.0.0, ≤ 10.0.72024-04-10
CVE-2024-31874 [MEDIUM] CWE-457 CVE-2024-31874: IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deployi
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow a local user to cause a denial of service. IBM X-Force ID: 287318.
nvd
← Previous2 / 2