Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.39%—IBM Verify Identity AccessAI15/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Pendiente de análisisAlta (7.2)0.32%—IBM Verify Identity AccessAI15/9/202616/9/2026
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
Pendiente de análisisAlta (7.5)0.16%—IBM Security Verify Identity Access Reverse ProxyAI15/9/202616/9/2026
IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Pendiente de análisisCrítica (9.8)0.29%—IBM Verify Identity AccessAI15/9/202617/9/2026
IBM Verify Identity Access is vulnerable to a buffer overflow attack.
Pendiente de análisisAlta (7.5)0.31%—IBM Verify Identity AccessAI15/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Pendiente de análisisCrítica (9.1)0.23%—IBM Verify Identity AccessAI15/9/202617/9/2026
IBM Verify Identity Access containers may not apply management password change operations correctly.
Pendiente de análisisAlta (8.1)0.27%—IBM Verify Identity AccessAI15/9/202619/9/2026
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.
Pendiente de análisisMedia (6.5)0.17%—IBM Security Verify Identity AccessAI15/9/202619/9/2026
IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.
Pendiente de análisisMedia (4.7)0.28%—IBM Verify Identity AccessAI14/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear…
Pendiente de análisisMedia (6.1)0.24%—IBM Verify Identity AccessAIIBM Security Verify AccessAIIBM Verify Identity Access ContainerAIIBM Security Verify Access ContainerAI14/9/202616/9/2026
IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001.
Pendiente de análisisAlta (7.5)0.43%—IBM Verify Identity AccessAI14/9/202616/9/2026
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Pendiente de análisisMedia (5.4)0.15%—IBM Verify Identity AccessAI14/9/202619/9/2026
IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.
Pendiente de análisisAlta (7.5)0.25%—IBM Verify Identity Access Advanced Access ControlAI4/9/20268/9/2026
IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.
AnalizadaCrítica (9.8)0.40%—IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
AnalizadaAlta (7.5)0.46%—IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202618/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnerable to a denial of service attack.
AnalizadaAlta (8.1)0.35%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request.
AnalizadaAlta (7.2)0.54%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
AnalizadaAlta (8.1)0.45%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy.
AnalizadaAlta (7.2)0.54%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a…
AnalizadaAlta (8.7)0.49%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of service and information disclosure by…
AnalizadaBaja (3.1)0.29%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack.
AnalizadaAlta (7.4)0.32%—IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container12/8/202617/8/2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
AnalizadaMedia (5.3)0.40%—IBM Verify Identity AccessIBM Verify Identity Access Container30/7/202612/8/2026
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error…
AnalizadaMedia (5.3)0.40%—IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container17/7/202611/8/2026
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
AnalizadaMedia (6.1)0.36%—IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container17/7/202630/7/2026
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect…