Vulnerabilities > IBM > Security Verify Access

DATE CVE VULNERABILITY TITLE RISK
2021-06-01 CVE-2021-29665 Out-of-bounds Write vulnerability in IBM Security Verify Access 20.07
IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with elevated privileges.
local
low complexity
ibm CWE-787
7.8
2020-10-15 CVE-2020-4499 Unspecified vulnerability in IBM Security Access Manager and Security Verify Access
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications.
network
low complexity
ibm
critical
9.8
2020-10-15 CVE-2019-4552 Unspecified vulnerability in IBM Security Access Manager and Security Verify Access
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks.
network
low complexity
ibm
6.1
2020-10-12 CVE-2020-4699 Information Exposure Through Discrepancy vulnerability in IBM Security Access Manager and Security Verify Access
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system.
high complexity
ibm CWE-203
5.3
2020-10-12 CVE-2020-4661 Information Exposure Through Discrepancy vulnerability in IBM Security Access Manager and Security Verify Access
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system.
high complexity
ibm CWE-203
5.3
2020-10-12 CVE-2020-4660 Information Exposure Through Discrepancy vulnerability in IBM Security Access Manager and Security Verify Access
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system.
high complexity
ibm CWE-203
5.3