VendorsIBMsecurity_verify_accessall versions
Vulnerabilities

IBM Security Verify Access

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

102CVEs
CVE-2021-20497
IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969
Published 2021-07-15 · Modified
7.5EPSS 0.007
CVE-2022-22464
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.
Published 2022-07-08 · Modified
7.5EPSS 0.007
CVE-2021-38921
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210067.
Published 2022-01-07 · Modified
7.5EPSS 0.007
CVE-2026-11932
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-08-12 · Analyzed
7.5EPSS 0.005
CVE-2022-32759
IBM Security Directory Server information disclosure
Published 2024-07-25 · Modified
7.5EPSS 0.004
CVE-2024-43187
IBM Security Verify Access information disclosure
Published 2025-02-04 · Analyzed
7.5EPSS 0.002
CVE-2026-11923
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-08-12 · Analyzed
7.4EPSS 0.003
CVE-2023-43016
IBM Security Access Manager Container unauthorized access
Published 2024-02-03 · Modified
7.3EPSS 0.007
CVE-2026-1345
Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-04-01 · Analyzed
7.3EPSS 0.004
CVE-2025-36354
IBM Security Verify Access command execution
Published 2025-10-06 · Analyzed
7.3EPSS 0.003
CVE-2026-12005
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-08-12 · Analyzed
7.2EPSS 0.005
CVE-2026-12618
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-08-12 · Analyzed
7.2EPSS 0.005
CVE-2026-1343
Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-04-08 · Analyzed
7.2EPSS 0.002
CVE-2023-32327
IBM Security Access Manager Container XML external entity injection
Published 2024-02-03 · Modified
7.1EPSS 0.010
CVE-2021-20511
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 198300.
Published 2021-07-15 · Modified
6.8EPSS 0.019
CVE-2021-29699
IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excuted by an user. IBM X-Force ID: 200600.
Published 2021-07-15 · Modified
6.8EPSS 0.009
CVE-2021-20510
IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 198299
Published 2021-07-15 · Modified
6.8EPSS 0.005
CVE-2024-28772
IBM Security Directory Integrator cross-site scripting
Published 2024-07-25 · Modified
6.8EPSS 0.003
CVE-2024-45657
IBM Security Verify Access incorrect privilege assignment
Published 2025-02-04 · Analyzed
6.7EPSS 0.001
CVE-2022-22463
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 225079.
Published 2022-07-08 · Modified
6.5EPSS 0.010
CVE-2022-22311
IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or possibly change some information due to improper validiation of JWT tokens.
Published 2022-03-31 · Modified
6.5EPSS 0.007
CVE-2021-20537
IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918
Published 2021-07-15 · Modified
6.5EPSS 0.007
CVE-2023-30433
IBM Security Verify Access HTTP open redirect
Published 2023-07-19 · Modified
6.5EPSS 0.004
CVE-2022-36775
IBM Security Verify Access HOST header injection
Published 2023-02-17 · Modified
6.5EPSS 0.004
CVE-2026-4938
Incorrect Authorization in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-07-17 · Analyzed
6.5EPSS 0.003
CVE-2026-5926
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-04-22 · Analyzed
6.5EPSS 0.002
CVE-2024-35138
IBM Security Verify Access cross-site request forgery
Published 2025-02-04 · Analyzed
6.5EPSS 0.002
CVE-2024-31874
IBM Security Verify Access Appliance denial of service
Published 2024-04-10 · Modified
6.2EPSS 0.003
CVE-2023-32329
IBM Security Access Manager Container improper file validation
Published 2024-02-03 · Modified
6.2EPSS 0.002
CVE-2023-38267
IBM Security Access Manager Appliance information disclosure
Published 2024-01-11 · Modified
6.2EPSS 0.001
CVE-2024-25027
IBM Security Verify Access Container information disclosure
Published 2024-03-31 · Modified
6.2EPSS 0.001
CVE-2019-4552
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 165960.
Published 2020-10-15 · Modified
6.1EPSS 0.009
CVE-2026-7364
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-07-17 · Analyzed
6.1EPSS 0.004
CVE-2024-40700
IBM Security Verify Access cross-site scripting
Published 2025-02-04 · Analyzed
6.1EPSS 0.003
CVE-2024-31883
IBM Security Verify Access denial of service
Published 2024-06-27 · Modified
5.9EPSS 0.006
CVE-2023-31001
IBM Security Access Manager Container information disclosure
Published 2024-01-11 · Modified
5.5EPSS 0.002
CVE-2023-30430
IBM Security Verify Access information disclosure
Published 2024-06-27 · Modified
5.5EPSS 0.002
CVE-2022-22370
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 221194.
Published 2022-07-08 · Modified
5.4EPSS 0.005
CVE-2021-38895
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209563.
Published 2022-01-07 · Modified
5.4EPSS 0.004
CVE-2026-4364
Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-04-01 · Analyzed
5.4EPSS 0.001
← Prev2 / 3Next →