Vulnerabilities > IBM > Security Identity Governance AND Intelligence > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-01-21 CVE-2020-4958 Missing Authentication for Critical Function vulnerability in IBM Security Identity Governance and Intelligence 5.2.6
IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
network
low complexity
ibm CWE-306
critical
9.8
2019-02-21 CVE-2018-1944 Use of Hard-coded Credentials vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
network
low complexity
ibm CWE-798
critical
9.8