VendorsIBMsecurity_verify_governanceall versions
Vulnerabilities

IBM Security Verify Governance

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2022-22466
IBM Security Verify Governance information disclosure
Published 2023-10-23 · Modified
9.8EPSS 0.006
CVE-2022-22455
IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 224989.
Published 2022-08-17 · Modified
9.8EPSS 0.005
CVE-2023-33836
IBM Security Verify Governance information disclosure
Published 2023-10-16 · Modified
9.8EPSS 0.004
CVE-2024-22330
IBM Security Verify Governance information disclosure
Published 2025-06-06 · Analyzed
9.8EPSS 0.003
CVE-2023-35019
IBM Security Verify Governance command execution
Published 2023-07-31 · Modified
8.8EPSS 0.013
CVE-2023-33839
IBM Security Verify Governance command execution
Published 2023-10-23 · Modified
8.8EPSS 0.011
CVE-2022-22452
IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918.
Published 2022-07-14 · Modified
7.5EPSS 0.010
CVE-2022-22460
IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013.
Published 2022-07-14 · Modified
7.5EPSS 0.007
CVE-2022-22462
IBM Security Verify Governance, Identity Manager virtual appliance component information disclosure
Published 2023-01-25 · Modified
7.5EPSS 0.005
CVE-2022-22461
IBM Security Verify Governance, Identity Manager information disclosure
Published 2022-12-22 · Modified
7.5EPSS 0.004
CVE-2022-22453
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.
Published 2022-07-14 · Modified
7.5EPSS 0.004
CVE-2025-36003
IBM Security Verify Governance Identity Manager information disclosure
Published 2025-08-28 · Analyzed
7.5EPSS 0.003
CVE-2023-33837
IBM Security Verify Governance information disclosure
Published 2023-10-23 · Modified
7.5EPSS 0.003
CVE-2023-35018
IBM Security Verify Governance file upload
Published 2023-10-15 · Modified
7.2EPSS 0.004
CVE-2023-35016
IBM Security Verify Governance path traversal
Published 2023-07-31 · Modified
6.5EPSS 0.012
CVE-2022-22458
IBM Security Verify Governance, Identity Manager information disclosure
Published 2022-12-22 · Modified
6.5EPSS 0.008
CVE-2022-22456
IBM Security Verify Governance, Identity Manager cross-site scripting
Published 2022-12-22 · Modified
6.1EPSS 0.003
CVE-2022-35646
IBM Security Verify Governance, Identity Manager security bypass
Published 2022-12-22 · Modified
5.9EPSS 0.004
CVE-2023-35888
IBM Security Verify Governance information disclosure
Published 2024-03-20 · Analyzed
5.9EPSS 0.003
CVE-2023-35017
IBM Security Verify Governance information
Published 2025-01-29 · Analyzed
5.9EPSS 0.002
CVE-2022-22470
IBM Security Verify Governance information disclosure
Published 2023-01-06 · Modified
5.5EPSS 0.001
CVE-2023-33844
IBM Security Verify Governance cross-site scripting
Published 2025-04-09 · Analyzed
5.4EPSS 0.002
CVE-2022-22449
IBM Security Verify Governance, Identity Manager information disclosure
Published 2022-12-22 · Modified
5.3EPSS 0.007
CVE-2022-22457
IBM Security Verify Governance, Identity Manager information disclosure
Published 2022-12-22 · Modified
5.3EPSS 0.001
CVE-2023-33838
IBM Security Verify Governance information disclosure
Published 2025-01-29 · Analyzed
4.9EPSS 0.002
CVE-2023-33840
IBM Security Verify Governance cross-site scripting
Published 2023-10-23 · Modified
4.8EPSS 0.003
CVE-2023-35013
IBM Security Verify Governance information disclosure
Published 2023-10-15 · Modified
4.4EPSS 0.002
CVE-2022-22450
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916.
Published 2022-07-14 · Modified
3.8EPSS 0.006