VendorsIBMsecurity_verify_accessall versions
Vulnerabilities

IBM Security Verify Access

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

102CVEs
CVE-2021-20585
IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system. IBM X-Force ID: 199398.
Published 2021-05-31 · Modified
5.3EPSS 0.010
CVE-2021-20498
IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further attacks against the system. IBM X-Force ID: 197972.
Published 2021-07-15 · Modified
5.3EPSS 0.009
CVE-2021-38956
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive version information in HTTP response headers that could aid in further attacks against the system. IBM X-Force ID: 212038
Published 2022-01-07 · Modified
5.3EPSS 0.009
CVE-2020-4660
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186140.
Published 2020-10-12 · Modified
5.3EPSS 0.005
CVE-2020-4661
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186142.
Published 2020-10-12 · Modified
5.3EPSS 0.005
CVE-2020-4699
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186947.
Published 2020-10-12 · Modified
5.3EPSS 0.005
CVE-2024-45658
IBM Security Verify Access information disclosure
Published 2025-02-04 · Analyzed
5.3EPSS 0.004
CVE-2026-8861
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-07-17 · Analyzed
5.3EPSS 0.004
CVE-2026-2862
Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-04-01 · Analyzed
5.3EPSS 0.004
CVE-2026-1491
Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-04-01 · Analyzed
5.3EPSS 0.004
CVE-2024-45659
IBM Security Verify Access information disclosure
Published 2025-02-04 · Analyzed
5.3EPSS 0.004
CVE-2025-0163
IBM Security Verify Access information disclosure
Published 2025-06-11 · Analyzed
5.3EPSS 0.003
CVE-2021-20496
IBM Security Verify Access Docker 10.0.0 could allow an authenticated user to bypass input due to improper input validation. IBM X-Force ID: 197966.
Published 2021-07-15 · Modified
4.9EPSS 0.006
CVE-2021-20534
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 198814
Published 2021-07-15 · Modified
4.9EPSS 0.005
CVE-2021-20524
IBM Security Verify Access Docker 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198661.
Published 2021-07-15 · Modified
4.8EPSS 0.005
CVE-2026-2475
Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-04-01 · Analyzed
4.7EPSS 0.003
CVE-2021-20500
IBM Security Verify Access Docker 10.0.0 could reveal highly sensitive information to a local privileged user. IBM X-Force ID: 197980.
Published 2021-07-15 · Modified
4.4EPSS 0.003
CVE-2021-20523
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 198660
Published 2021-07-15 · Modified
4.0EPSS 0.010
CVE-2021-20499
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 197973
Published 2021-07-15 · Modified
4.0EPSS 0.010
CVE-2021-38894
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 209515.
Published 2022-01-07 · Modified
4.0EPSS 0.009
CVE-2021-20575
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278.
Published 2021-05-31 · Modified
4.0EPSS 0.003
CVE-2026-11937
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published 2026-08-12 · Analyzed
3.1EPSS 0.003
← Prev3 / 3