cbcvebase.

Ibm Security Verify Access Docker vulnerabilities

49 known vulnerabilities affecting ibm/security_verify_access_docker.

Total CVEs
49
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH19MEDIUM21LOW3

Vulnerabilities

Page 2 of 3
CVE-2023-31006P3HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-31006 [HIGH] CWE-400 CVE-2023-31006: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to a denial of service attacks on the DSC server. IBM X-Force ID: 254776.
nvd
CVE-2024-35140P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.7≥ 10.0.0, ≤ 10.0.62024-05-31
CVE-2024-35140 [HIGH] CWE-295 CVE-2024-35140: IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their p IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation. IBM X-Force ID: 292416.
nvd
CVE-2021-20497P3HIGHCVSS 7.5v10.0.02021-07-15
CVE-2021-20497 [HIGH] CWE-327 CVE-2021-20497: IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that cou IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969
nvd
CVE-2021-29742P3HIGHCVSS 8.0v10.0.02021-07-15
CVE-2021-29742 [HIGH] CVE-2021-29742: IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the syste IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the system. IBM X-Force ID: 201483.
nvd
CVE-2023-30999P3HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-30999 [HIGH] CWE-400 CVE-2023-30999: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 254651.
nvd
CVE-2021-20537P3MEDIUMCVSS 6.5v10.0.02021-07-15
CVE-2021-20537 [MEDIUM] CWE-798 CVE-2021-20537: IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryp IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918
nvd
CVE-2022-36775P4MEDIUMCVSS 6.5v10.0.0.0v10.0.1.0+3 more2023-02-17
CVE-2022-36775 [MEDIUM] CWE-74 CVE-2022-36775: IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID:
nvd
CVE-2021-20511P4MEDIUMCVSS 4.9v10.0.02021-07-15
CVE-2021-20511 [MEDIUM] CWE-22 CVE-2021-20511: IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on th IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 198300.
nvd
CVE-2021-29699P4MEDIUMCVSS 6.8v10.0.02021-07-15
CVE-2021-29699 [MEDIUM] CWE-434 CVE-2021-29699: IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary file IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excuted by an user. IBM X-Force ID: 200600.
nvd
CVE-2025-0163P4MEDIUMCVSS 5.3≥ 10.0.0, < 10.0.9≥ 10.0, ≤ 10.0.82025-06-11
CVE-2025-0163 [MEDIUM] CWE-204 CVE-2025-0163: IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
nvd
CVE-2024-45657P4MEDIUMCVSS 6.7≥ 10.0.0.0, < 10.0.9.02025-02-04
CVE-2024-45657 [MEDIUM] CWE-732 CVE-2024-45657: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privile IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.
nvd
CVE-2024-35137P4MEDIUMCVSS 6.2≥ 10.0.0.0, ≤ 10.0.7.12024-06-28
CVE-2024-35137 [MEDIUM] CWE-258 CVE-2024-35137: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly el IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.
nvd
CVE-2024-40700P4MEDIUMCVSS 6.1≥ 10.0.0.0, < 10.0.9.02025-02-04
CVE-2024-40700 [MEDIUM] CWE-79 CVE-2024-40700: IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2021-20498P4MEDIUMCVSS 5.3v10.0.02021-07-15
CVE-2021-20498 [MEDIUM] CWE-200 CVE-2021-20498: IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further attacks against the system. IBM X-Force ID: 197972.
nvd
CVE-2023-38267P4MEDIUMCVSS 5.5≥ 10.0.0.0, < 10.0.0.7≥ 10.0.0.0, ≤ 10.0.6.12024-01-11
CVE-2023-38267 [MEDIUM] CWE-311 CVE-2023-38267: IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 260584.
nvd
CVE-2023-31002P4MEDIUMCVSS 5.5≥ 10.0.0.0, ≤ 10.0.6.12024-02-07
CVE-2023-31002 [MEDIUM] CWE-312 CVE-2023-31002: IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive informa IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.
nvd
CVE-2023-31001P4MEDIUMCVSS 5.5≥ 10.0.0.0, < 10.0.0.7≥ 10.0.0.0, ≤ 10.0.6.12024-01-11
CVE-2023-31001 [MEDIUM] CWE-257 CVE-2023-31001: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254653.
nvd
CVE-2023-30433P4MEDIUMCVSS 5.4v10.02023-07-19
CVE-2023-30433 [MEDIUM] CWE-601 CVE-2023-30433: IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could all
nvd
CVE-2023-32329P4MEDIUMCVSS 5.5≥ 10.0.0.0, ≤ 10.0.6.12024-02-03
CVE-2023-32329 [MEDIUM] CWE-345 CVE-2023-32329: IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6. IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to improper file validation. IBM X-Force ID: 254972.
nvd
CVE-2024-25027P4MEDIUMCVSS 5.5v10.0.62024-03-31
CVE-2024-25027 [MEDIUM] CWE-311 CVE-2024-25027: IBM Security Verify Access 10.0.6 could disclose sensitive snapshot information due to missing encry IBM Security Verify Access 10.0.6 could disclose sensitive snapshot information due to missing encryption. IBM X-Force ID: 281607.
nvd
Ibm Security Verify Access Docker vulnerabilities | cvebase