IBM Security Verify Governance 10.0.1

CPE Details

IBM Security Verify Governance 10.0.1
10.0.1
2022-12-23
16h17 +00:00
2023-02-28
20h49 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ibm:security_verify_governance:10.0.1:*:*:*:*:*:*:*

Informations

Vendor

ibm

Product

security_verify_governance

Version

10.0.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-33839 2023-10-23 19h45 +00:00 IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 256036.
8.8
High
CVE-2022-22466 2023-10-23 19h42 +00:00 IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 225222.
9.8
Critical
CVE-2023-33840 2023-10-23 19h36 +00:00 IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 256037.
4.8
Medium
CVE-2023-33836 2023-10-16 00h26 +00:00 IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 256016.
9.8
Critical
CVE-2023-35018 2023-10-15 23h46 +00:00 IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.
7.2
High
CVE-2023-35013 2023-10-15 23h43 +00:00 IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769.
4.4
Medium
CVE-2022-22462 2023-01-25 18h59 +00:00 IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225078.
7.5
High
CVE-2022-22449 2022-12-22 21h26 +00:00 IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 224915.
5.3
Medium
CVE-2022-22457 2022-12-22 21h20 +00:00 IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007.
5.3
Medium
CVE-2022-22458 2022-12-22 21h14 +00:00 IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user. IBM X-Force ID: 225009.
6.5
Medium
CVE-2022-22456 2022-12-22 21h08 +00:00 IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225004.
6.1
Medium
CVE-2022-22461 2022-12-22 19h39 +00:00 IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225007.
7.5
High
CVE-2022-35646 2022-12-22 19h08 +00:00 IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using man-in-the-middle techniques. IBM X-Force ID: 231096.  
5.9
Medium