Vulnerabilities > IBM > Security Verify Access > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-07-08 | CVE-2022-22463 | SQL Injection vulnerability in IBM Security Verify Access IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. | 6.5 |
2022-03-31 | CVE-2022-22311 | Improper Input Validation vulnerability in IBM Security Verify Access IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens. | 6.5 |
2022-01-10 | CVE-2021-38895 | Cross-site Scripting vulnerability in IBM Security Verify Access 10.0.0/10.0.1.0/10.0.2.0 IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 is vulnerable to cross-site scripting. | 5.4 |
2022-01-10 | CVE-2021-38956 | Information Exposure vulnerability in IBM Security Verify Access 10.0.0/10.0.1.0/10.0.2.0 IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive version information in HTTP response headers that could aid in further attacks against the system. | 5.3 |
2021-07-15 | CVE-2021-20496 | Improper Input Validation vulnerability in IBM Security Verify Access 10.0.0 IBM Security Verify Access Docker 10.0.0 could allow an authenticated user to bypass input due to improper input validation. | 4.9 |
2021-07-15 | CVE-2021-20498 | Information Exposure vulnerability in IBM Security Verify Access 10.0.0 IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further attacks against the system. | 5.3 |
2021-07-15 | CVE-2021-20500 | Unspecified vulnerability in IBM Security Verify Access 10.0.0 IBM Security Verify Access Docker 10.0.0 could reveal highly sensitive information to a local privileged user. | 4.4 |
2021-07-15 | CVE-2021-20510 | Cleartext Storage of Sensitive Information vulnerability in IBM Security Verify Access 10.0.0 IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by a local user. | 4.4 |
2021-07-15 | CVE-2021-20511 | Path Traversal vulnerability in IBM Security Verify Access 10.0.0 IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on the system. | 4.9 |
2021-07-15 | CVE-2021-20524 | Cross-site Scripting vulnerability in IBM Security Verify Access 10.0.0 IBM Security Verify Access Docker 10.0.0 is vulnerable to cross-site scripting. | 4.8 |