Vulnerabilities > IBM > Security Verify Governance > 10.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-08-17 | CVE-2022-22455 | Unspecified vulnerability in IBM Security Verify Governance 10.0 IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. | 9.8 |
2022-07-14 | CVE-2022-22450 | Unrestricted Upload of File with Dangerous Type vulnerability in IBM Security Verify Governance 10.0 IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. | 3.8 |
2022-07-14 | CVE-2022-22452 | Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Security Verify Governance 10.0 IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. | 7.5 |
2022-07-14 | CVE-2022-22453 | Inadequate Encryption Strength vulnerability in IBM Security Verify Governance 10.0 IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 7.5 |
2022-07-14 | CVE-2022-22460 | Unspecified vulnerability in IBM Security Verify Governance 10.0 IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. | 7.5 |