Ibm Security Verify Governance vulnerabilities
28 known vulnerabilities affecting ibm/security_verify_governance.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH9MEDIUM14LOW1
Vulnerabilities
Page 2 of 2
CVE-2022-22457MEDIUMCVSS 4.4v10.0.12022-12-22
CVE-2022-22457 [MEDIUM] CWE-319 CVE-2022-22457: IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007.
nvd
CVE-2022-22458MEDIUMCVSS 6.5v10.0.12022-12-22
CVE-2022-22458 [MEDIUM] CWE-256 CVE-2022-22458:
IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text
IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user. IBM X-Force ID: 225009.
nvd
CVE-2022-22456MEDIUMCVSS 6.1v10.0.12022-12-22
CVE-2022-22456 [MEDIUM] CWE-79 CVE-2022-22456:
IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This
IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225004.
nvd
CVE-2022-22455CRITICALCVSS 9.8v10.02022-08-17
CVE-2022-22455 [CRITICAL] CVE-2022-22455: IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operati
IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 224989.
cvelistv5nvd
CVE-2022-22452HIGHCVSS 7.5v10.02022-07-14
CVE-2022-22452 [HIGH] CWE-307 CVE-2022-22452: IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allo
IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918.
cvelistv5nvd
CVE-2022-22460HIGHCVSS 7.5v10.02022-07-14
CVE-2022-22460 [HIGH] CVE-2022-22460: IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code reposito
IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013.
cvelistv5nvd
CVE-2022-22453HIGHCVSS 7.5v10.02022-07-14
CVE-2022-22453 [HIGH] CWE-326 CVE-2022-22453: IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that co
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.
cvelistv5nvd
CVE-2022-22450LOWCVSS 3.8v10.02022-07-14
CVE-2022-22450 [LOW] CWE-434 CVE-2022-22450: IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file b
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916.
cvelistv5nvd
← Previous2 / 2