VYPR

Security Verify Access

by IBM

CVEs (116)

  • CVE-2021-29742HigJul 15, 2021
    risk 0.52cvss 8.0epss 0.00

    IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the system. IBM X-Force ID: 201483.

  • CVE-2025-0161HigFeb 20, 2025
    risk 0.51cvss 7.8epss 0.00

    IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restrictions on code generation.

  • CVE-2024-49814HigFeb 6, 2025
    risk 0.51cvss 7.8epss 0.00

    IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges.

  • CVE-2024-49804HigNov 29, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks.

  • CVE-2022-22465HigJul 8, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local user to obtain elevated privileges due to improper access permissions. IBM X-Force ID: 225082.

  • CVE-2021-29665HigJun 1, 2021
    risk 0.51cvss 7.8epss 0.01

    IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with elevated privileges.

  • CVE-2024-35140HigMay 31, 2024
    risk 0.50cvss 7.7epss 0.00

    IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation. IBM X-Force ID: 292416.

  • CVE-2024-31873HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor. IBM X-Force ID: 287317.

  • CVE-2024-31872HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.

  • CVE-2024-31871HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. IBM X-Force ID: 287306.

  • CVE-2023-32330HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977.

  • CVE-2023-32328HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957.

  • CVE-2023-30999HigFeb 3, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: …

  • CVE-2022-43740HigOct 14, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 238921.

  • CVE-2022-22464HigJul 8, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.

  • CVE-2021-38957HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.

  • CVE-2021-38921HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210067.

  • CVE-2021-20497HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969

  • CVE-2021-20439HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.

  • CVE-2021-20576HigJun 1, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash.

Page 2 of 6