Vulnerabilities > IBM > Security Verify Access Docker > 10.0.0

DATE CVE VULNERABILITY TITLE RISK
2025-01-20 CVE-2024-45647 Unspecified vulnerability in IBM products
IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.
network
low complexity
ibm
critical
9.8
2024-12-19 CVE-2024-35141 Unspecified vulnerability in IBM Security Verify Access Docker
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.
local
low complexity
ibm
7.8
2024-08-29 CVE-2024-35133 Open Redirect vulnerability in IBM products
IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
8.2
2024-05-31 CVE-2024-35140 Unspecified vulnerability in IBM Security Verify Access Docker
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation.
local
low complexity
ibm
7.8
2024-05-31 CVE-2024-35142 Unspecified vulnerability in IBM Security Verify Access Docker
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.
local
low complexity
ibm
7.8
2022-02-02 CVE-2021-39070 Unspecified vulnerability in IBM products
IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system.
network
low complexity
ibm
critical
9.8