IBM
IBM Security Verify Privilege On-premises: vulnerabilities and CVEs
IBM Security Verify Privilege On-premises has 15 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs15
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31887 | High (7.5) | 0.52% | — | Apr 16, 2024 | IBM Security Verify Privilege 11.6.25 could allow an unauthenticated actor to obtain sensitive information from the SOAP API. IBM X-Force ID: 287651. |
| CVE-2022-43890 | High (7.5) | 0.42% | — | Mar 4, 2024 | IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240453. |
| CVE-2022-43892 | Medium (5.3) | 0.26% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information which could aid further attacks against the system. IBM X-Force ID:… |
| CVE-2022-43891 | Medium (5.3) | 0.53% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further… |
| CVE-2022-43893 | Medium (4.4) | 0.41% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could allow a privileged user to cause by using a malicious payload. IBM X-Force ID: 240634. |
| CVE-2022-43889 | Medium (5.3) | 0.45% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240452. |
| CVE-2022-22386 | Medium (5.9) | 0.48% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this… |
| CVE-2022-22385 | High (7.5) | 0.41% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmission of data in clear text. IBM X-Force ID: 221962. |
| CVE-2022-22380 | Medium (4.3) | 0.24% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity due to improperly validating certificates. IBM X-Force ID: 221957. |
| CVE-2022-22375 | High (8.8) | 1.2% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681. |
| CVE-2021-38859 | Medium (5.3) | 0.53% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that could be used in further attacks against the system. IBM X-Force ID:… |
| CVE-2021-29913 | High (7.1) | 0.41% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 207898. |
| CVE-2021-20581 | Medium (4.3) | 0.38% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324. |
| CVE-2022-22384 | Medium (4.3) | 0.44% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due to hazardous input validation. IBM X-Force ID: 221961. |
| CVE-2022-22377 | Medium (5.3) | 0.48% | — | Oct 17, 2023 | IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this… |
Other products by IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142