VendorsIBMsecurity_verify_governance10.0
Vulnerabilities

IBM Security Verify Governance 10.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2022-22455
IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 224989.
Published 2022-08-17 · Modified
9.8EPSS 0.005
CVE-2023-35019
IBM Security Verify Governance command execution
Published 2023-07-31 · Modified
8.8EPSS 0.013
CVE-2023-33839
IBM Security Verify Governance command execution
Published 2023-10-23 · Modified
8.8EPSS 0.011
CVE-2022-22452
IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918.
Published 2022-07-14 · Modified
7.5EPSS 0.010
CVE-2022-22460
IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013.
Published 2022-07-14 · Modified
7.5EPSS 0.007
CVE-2022-22453
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.
Published 2022-07-14 · Modified
7.5EPSS 0.004
CVE-2023-33837
IBM Security Verify Governance information disclosure
Published 2023-10-23 · Modified
7.5EPSS 0.003
CVE-2023-35016
IBM Security Verify Governance path traversal
Published 2023-07-31 · Modified
6.5EPSS 0.012
CVE-2022-22470
IBM Security Verify Governance information disclosure
Published 2023-01-06 · Modified
5.5EPSS 0.001
CVE-2023-33840
IBM Security Verify Governance cross-site scripting
Published 2023-10-23 · Modified
4.8EPSS 0.003
CVE-2022-22450
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916.
Published 2022-07-14 · Modified
3.8EPSS 0.006