Ibm Security Verify Governance vulnerabilities
28 known vulnerabilities affecting ibm/security_verify_governance.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH9MEDIUM14LOW1
Vulnerabilities
Page 2 of 2
CVE-2023-33844P4MEDIUMCVSS 5.4v10.0.22025-04-09
CVE-2023-33844 [MEDIUM] CWE-79 CVE-2023-33844: IBM Security Verify Governance 10.0.2 is vulnerable to cross-site scripting. This vulnerability allo
IBM Security Verify Governance 10.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2023-33838P4MEDIUMCVSS 4.9v10.0.22025-01-29
CVE-2023-33838 [MEDIUM] CWE-759 CVE-2023-33838: IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against a
IBM Security Verify Governance 10.0.2 Identity Manager
uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
nvd
CVE-2022-22449P4MEDIUMCVSS 5.3v10.0.12022-12-24
CVE-2022-22449 [MEDIUM] CWE-209 CVE-2022-22449: IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensi
IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 224915.
nvd
CVE-2022-22470P4MEDIUMCVSS 5.5v10.02023-01-09
CVE-2022-22470 [MEDIUM] CWE-312 CVE-2022-22470: IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read b
IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225232.
nvd
CVE-2023-33840P4MEDIUMCVSS 4.8v10.0v10.0.12023-10-23
CVE-2023-33840 [MEDIUM] CWE-79 CVE-2023-33840: IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows
IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 256037.
nvd
CVE-2023-35013P4MEDIUMCVSS 4.4≥ 10.0, < 10.0.2v10.02023-10-16
CVE-2023-35013 [MEDIUM] CWE-540 CVE-2023-35013: IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769.
nvd
CVE-2022-22457P4MEDIUMCVSS 4.4v10.0.12022-12-22
CVE-2022-22457 [MEDIUM] CWE-319 CVE-2022-22457: IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007.
nvd
CVE-2022-22450P4LOWCVSS 3.8v10.02022-07-14
CVE-2022-22450 [LOW] CWE-434 CVE-2022-22450: IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file b
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916.
nvd
← Previous2 / 2