Vulnerabilities > IBM > Security Verify Governance > 10.0

DATE CVE VULNERABILITY TITLE RISK
2022-08-17 CVE-2022-22455 Unspecified vulnerability in IBM Security Verify Governance 10.0
IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
network
low complexity
ibm
critical
9.8
2022-07-14 CVE-2022-22450 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Security Verify Governance 10.0
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request.
network
low complexity
ibm CWE-434
3.8
2022-07-14 CVE-2022-22452 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Security Verify Governance 10.0
IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
network
low complexity
ibm CWE-307
7.5
2022-07-14 CVE-2022-22453 Inadequate Encryption Strength vulnerability in IBM Security Verify Governance 10.0
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2022-07-14 CVE-2022-22460 Unspecified vulnerability in IBM Security Verify Governance 10.0
IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system.
network
low complexity
ibm
7.5