VYPR

Security Directory Server

by IBM

CVEs (35)

  • CVE-2022-33164HigSep 8, 2023
    risk 0.57cvss 8.7epss 0.01

    IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view or write to arbitrary files on the system. IBM X-Force ID: 228579.

  • CVE-2019-4538HigOct 2, 2019
    risk 0.53cvss 8.2epss 0.01

    IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a…

  • CVE-2015-1975HigApr 3, 2018
    risk 0.51cvss 7.8epss 0.00

    The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before iFix 2 allows local users to gain privileges via vectors…

  • CVE-2022-32757HigJun 15, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 228510.

  • CVE-2022-33168HigJun 15, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Security Directory Suite VA 8.0.1 could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 228588.

  • CVE-2019-4540HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813.

  • CVE-2019-4520HigOct 2, 2019
    risk 0.49cvss 7.5epss 0.02

    IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 165178.

  • CVE-2015-1977HigJul 15, 2016
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before 6.2.0.50-ISS-ISDS-IF0050, and 6.3.x before 6.3.0.43-ISS-ISDS-IF0043 and IBM Security Directory Server (ISDS) before…

  • CVE-2022-33162HigAug 16, 2024
    risk 0.47cvss 7.3epss 0.00

    IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources, at the privilege level of a standard unprivileged…

  • CVE-2022-33166HigJun 15, 2023
    risk 0.47cvss 7.2epss 0.01

    IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 228586.

  • CVE-2022-32752HigJun 15, 2023
    risk 0.47cvss 7.2epss 0.01

    IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 228439.

  • CVE-2019-4541HigFeb 4, 2020
    risk 0.47cvss 7.2epss 0.01

    IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 165814.

  • CVE-2019-4539HigOct 2, 2019
    risk 0.46cvss 7.1epss 0.01

    IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system. IBM X-Force ID: 165812.

  • CVE-2024-28767MedDec 20, 2024
    risk 0.44cvss 6.8epss 0.01

    IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

  • CVE-2024-28772MedJul 25, 2024
    risk 0.44cvss 6.8epss 0.00

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading…

  • CVE-2022-33165MedOct 14, 2023
    risk 0.44cvss 6.8epss 0.01

    IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 228582.

  • CVE-2019-4548MedFeb 4, 2020
    risk 0.40cvss 6.1epss 0.01

    IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch…

  • CVE-2019-4542MedOct 2, 2019
    risk 0.40cvss 6.1epss 0.01

    IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM…

  • CVE-2022-32755MedOct 14, 2023
    risk 0.36cvss 5.5epss 0.01

    IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.

  • CVE-2015-1976MedFeb 8, 2017
    risk 0.36cvss 5.5epss 0.00

    IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.

Page 1 of 2