IBM
IBM Security Verify Governance: vulnerabilidades y CVE
IBM Security Verify Governance tiene 28 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-36003 | Media (5.3) | 0.34% | — | 28 ago 2025 | IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks… |
| CVE-2024-22330 | Crítica (9.8) | 0.33% | — | 6 jun 2025 | IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. |
| CVE-2023-33844 | Media (5.4) | 0.23% | — | 9 abr 2025 | IBM Security Verify Governance 10.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading… |
| CVE-2023-33838 | Media (4.9) | 0.24% | — | 29 ene 2025 | IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input. |
| CVE-2023-35017 | Media (5.9) | 0.24% | — | 29 ene 2025 | IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques. |
| CVE-2023-35888 | Media (5.9) | 0.32% | — | 20 mar 2024 | IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability… |
| CVE-2023-33840 | Media (4.8) | 0.32% | — | 23 oct 2023 | IBM Security Verify Governance 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… |
| CVE-2023-33839 | Alta (8.8) | 1.1% | — | 23 oct 2023 | IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 256036. |
| CVE-2023-33837 | Alta (7.5) | 0.26% | — | 23 oct 2023 | IBM Security Verify Governance 10.0 does not encrypt sensitive or critical information before storage or transmission. IBM X-Force ID: 256020. |
| CVE-2022-22466 | Crítica (9.8) | 0.59% | — | 23 oct 2023 | IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or… |
| CVE-2023-33836 | Crítica (9.8) | 0.44% | — | 16 oct 2023 | IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or… |
| CVE-2023-35018 | Alta (7.2) | 0.37% | — | 16 oct 2023 | IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382. |
| CVE-2023-35013 | Media (4.4) | 0.17% | — | 16 oct 2023 | IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769. |
| CVE-2023-35019 | Alta (8.8) | 1.3% | — | 31 jul 2023 | IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 257873. |
| CVE-2023-35016 | Media (6.5) | 1.2% | — | 31 jul 2023 | IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to… |
| CVE-2022-22462 | Alta (7.5) | 0.48% | — | 26 ene 2023 | IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force… |
| CVE-2022-22470 | Media (5.5) | 0.12% | — | 9 ene 2023 | IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225232. |
| CVE-2022-22449 | Media (5.3) | 0.72% | — | 24 dic 2022 | IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in… |
| CVE-2022-22458 | Media (6.5) | 0.79% | — | 22 dic 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user. IBM X-Force ID: 225009. |
| CVE-2022-22457 | Media (4.4) | 0.13% | — | 22 dic 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007. |
| CVE-2022-22456 | Media (6.1) | 0.31% | — | 22 dic 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality… |
| CVE-2022-35646 | Media (5.3) | 0.38% | — | 22 dic 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using man-in-the-middle techniques. IBM X-Force ID: 231096. |
| CVE-2022-22461 | Alta (7.5) | 0.41% | — | 22 dic 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225007. |
| CVE-2022-22455 | Crítica (9.8) | 0.50% | — | 17 ago 2022 | IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the… |
| CVE-2022-22460 | Alta (7.5) | 0.74% | — | 14 jul 2022 | IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013. |
| CVE-2022-22453 | Alta (7.5) | 0.40% | — | 14 jul 2022 | IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919. |
| CVE-2022-22452 | Alta (7.5) | 0.99% | — | 14 jul 2022 | IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918. |
| CVE-2022-22450 | Baja (3.8) | 0.60% | — | 14 jul 2022 | IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142