Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.24% | — | IBM Security Verify Governance | 29/1/2025 | 17/6/2026 | IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input. | |
| Analizada | Media (5.9) | 0.24% | — | IBM Security Verify Governance | 29/1/2025 | 17/6/2026 | IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques. | |
| Analizada | Media (6.5) | 0.18% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie… | |
| Analizada | Media (6.5) | 0.18% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie… | |
| Analizada | Alta (7.5) | 0.32% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system. | |
| Analizada | Media (6) | 0.14% | — | IBM Security Verify Bridge | 23/1/2025 | 17/6/2026 | IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a denial of service. | |
| Analizada | Crítica (9.8) | 0.27% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 20/1/2025 | 17/6/2026 | IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password. | |
| Modificada | Alta (7.8) | 0.23% | — | IBM Security Verify Access Docker | 19/12/2024 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. | |
| Analizada | Crítica (9.8) | 0.32% | — | IBM Security Verify Access | 29/11/2024 | 17/6/2026 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | |
| Analizada | Crítica (9.8) | 0.33% | — | IBM Security Verify Access | 29/11/2024 | 17/6/2026 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | |
| Analizada | Alta (7.8) | 0.18% | — | IBM Security Verify Access | 29/11/2024 | 17/6/2026 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to perform certain tasks. | |
| Analizada | Alta (8.8) | 0.77% | — | IBM Security Verify Access | 29/11/2024 | 17/6/2026 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. | |
| Modificada | Alta (8.2) | 1.8% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 29/8/2024 | 17/6/2026 | IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect… | |
| Modificada | Crítica (9.8) | 0.43% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 16/8/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources, at the privilege level of a standard unprivileged user. IBM X-Force ID: 228570. | |
| Modificada | Alta (7.5) | 0.43% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 30/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID:… | |
| Modificada | Media (5.4) | 0.28% | — | IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access | 25/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Modificada | Alta (7.5) | 0.38% | — | IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access | 25/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565. | |
| Modificada | Media (5.9) | 0.59% | — | IBM Security Verify Access | 27/6/2024 | 17/6/2026 | IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow an unauthenticated attacker to cause a denial of service due to asymmetric resource consumption. IBM X-Force ID: 287615. | |
| Modificada | Media (5.5) | 0.16% | — | IBM Security Verify Access | 27/6/2024 | 17/6/2026 | IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace logs. IBM X-Force ID: 252183. | |
| Modificada | Alta (7.8) | 0.23% | — | IBM Security Verify Access Docker | 31/5/2024 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. IBM X-Force ID: 292418. | |
| Modificada | Alta (7.8) | 0.13% | — | IBM Security Verify Access Docker | 31/5/2024 | 17/6/2026 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation. IBM X-Force ID: 292416. | |
| Analizada | Media (5.5) | 0.15% | — | IBM Security Verify Access Oidc Provider | 31/5/2024 | 17/6/2026 | IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: 279978. | |
| Analizada | Alta (7.5) | 0.52% | — | IBM Security Verify Privilege On-premises | 16/4/2024 | 17/6/2026 | IBM Security Verify Privilege 11.6.25 could allow an unauthenticated actor to obtain sensitive information from the SOAP API. IBM X-Force ID: 287651. | |
| Modificada | Media (5.5) | 0.29% | — | IBM Security Verify Access | 10/4/2024 | 17/6/2026 | IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow a local user to cause a denial of service. IBM X-Force ID: 287318. | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Security Verify Access | 10/4/2024 | 17/6/2026 | IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor. IBM X-Force ID: 287317. |