Ibm Verify Identity Access Container vulnerabilities
37 known vulnerabilities affecting ibm/verify_identity_access_container.
Total CVEs
37
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH18MEDIUM13LOW1
Vulnerabilities
Page 2 of 2
CVE-2026-4938P3MEDIUMCVSS 6.5≥ 11.0.0.0, ≤ 11.0.2.0≥ 11.0, ≤ 11.0.22026-07-17
CVE-2026-4938 [MEDIUM] CWE-863 CVE-2026-4938: IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow an attacker with read-only privileges to make unauthorized modifications and deployments outside of their assigned per
nvd
CVE-2026-13260P3HIGHCVSS 7.5≥ 11.0.0, ≤ 11.0.3 Interim Fix 0012026-09-14
CVE-2026-13260 [HIGH] CWE-770 CVE-2026-13260: IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insuffi
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
nvd
CVE-2026-12358P3HIGHCVSS 7.5≥ 11.0.0, ≤ 11.0.3 Interim Fix 0012026-09-15
CVE-2026-12358 [HIGH] CWE-674 CVE-2026-12358: IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insuffi
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
nvd
CVE-2026-11926P3HIGHCVSS 7.5≥ 11.0.0, ≤ 11.0.3 Interim Fix 0012026-09-15
CVE-2026-11926 [HIGH] CWE-400 CVE-2026-11926: IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insuffi
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
nvd
CVE-2026-5926P3MEDIUMCVSS 6.5≥ 11.0.0.0, ≤ 11.0.2.0≥ 11.0, ≤ 11.0.22026-04-23
CVE-2026-5926 [MEDIUM] CWE-327 CVE-2026-5926: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
nvd
CVE-2026-11927P3MEDIUMCVSS 6.5≥ 11.0.0, ≤ 11.0.3 Interim Fix 0012026-09-15
CVE-2026-11927 [MEDIUM] CWE-74 CVE-2026-11927: IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to
IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.
nvd
CVE-2026-7364P4MEDIUMCVSS 6.1≥ 11.0.0.0, ≤ 11.0.2.0≥ 11.0, ≤ 11.0.22026-07-17
CVE-2026-7364 [MEDIUM] CWE-601 CVE-2026-7364: IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit thi
nvd
CVE-2026-2862P4MEDIUMCVSS 5.3≥ 11.0.0.0, ≤ 11.0.2.0≥ 11.0, ≤ 11.0.22026-04-01
CVE-2026-2862 [MEDIUM] CWE-444 CVE-2026-2862: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTT
nvd
CVE-2026-1491P4MEDIUMCVSS 5.3≥ 11.0.0.0, ≤ 11.0.2.0≥ 11.0, ≤ 11.0.22026-04-01
CVE-2026-1491 [MEDIUM] CWE-444 CVE-2026-1491: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTT
nvd
CVE-2026-13276P4MEDIUMCVSS 6.1≥ 11.0.0, ≤ 11.0.3 Interim Fix 0012026-09-14
CVE-2026-13276 [MEDIUM] CWE-79 CVE-2026-13276: IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0
IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001.
nvd
CVE-2026-11904P4MEDIUMCVSS 5.3≥ 10.0.0.0, ≤ 10.0.9.1≥ 11.0.0.0, ≤ 11.0.2+1 more2026-07-30
CVE-2026-11904 [MEDIUM] CWE-209 CVE-2026-11904: IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser
nvd
CVE-2026-13272P4MEDIUMCVSS 5.4≥ 11.0.0, ≤ 11.0.3 Interim Fix 0012026-09-14
CVE-2026-13272 [MEDIUM] CWE-1385 CVE-2026-13272: IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perfo
IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.
nvd
CVE-2026-4364P4MEDIUMCVSS 5.4≥ 11.0.0.0, ≤ 11.0.2.0≥ 11.0, ≤ 11.0.22026-04-01
CVE-2026-4364 [MEDIUM] CWE-79 CVE-2026-4364: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows certificate listings retrieved via a browser session to return a JSON payload while incorrectly specifying the response Con
nvd
CVE-2026-8861P4MEDIUMCVSS 5.3≥ 11.0.0.0, ≤ 11.0.2≥ 11.0, ≤ 11.0.22026-07-17
CVE-2026-8861 [MEDIUM] CWE-209 CVE-2026-8861: IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed te
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
nvd
CVE-2026-2475P4MEDIUMCVSS 4.7≥ 11.0.0.0, ≤ 11.0.2.0≥ 11.0, ≤ 11.0.22026-04-01
CVE-2026-2475 [MEDIUM] CWE-601 CVE-2026-2475: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit th
nvd
CVE-2026-13277P4MEDIUMCVSS 4.7≥ 11.0.0, ≤ 11.0.3 Interim Fix 0012026-09-14
CVE-2026-13277 [MEDIUM] CWE-601 CVE-2026-13277: IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open
IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow th
nvd
CVE-2026-11937P4LOWCVSS 3.1≥ 11.0.0.0, ≤ 11.0.3.0≥ 11.0, ≤ 11.0.32026-08-12
CVE-2026-11937 [LOW] CWE-416 CVE-2026-11937: IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack.
nvd
← Previous2 / 2