IBM
IBM Verify Identity Access: vulnerabilidades y CVE
IBM Verify Identity Access tiene 37 vulnerabilidades publicadas, 37 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE37
Últimos 12 meses37
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-12358 | Alta (7.5) | 0.39% | — | 15 sept 2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. |
| CVE-2026-11934 | Alta (7.2) | 0.32% | — | 15 sept 2026 | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input. |
| CVE-2026-11928 | Crítica (9.8) | 0.29% | — | 15 sept 2026 | IBM Verify Identity Access is vulnerable to a buffer overflow attack. |
| CVE-2026-11926 | Alta (7.5) | 0.31% | — | 15 sept 2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. |
| CVE-2026-11921 | Crítica (9.1) | 0.23% | — | 15 sept 2026 | IBM Verify Identity Access containers may not apply management password change operations correctly. |
| CVE-2026-12101 | Alta (8.1) | 0.27% | — | 15 sept 2026 | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests. |
| CVE-2026-13277 | Media (4.7) | 0.28% | — | 14 sept 2026 | IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this… |
| CVE-2026-13276 | Media (6.1) | 0.24% | — | 14 sept 2026 | IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and… |
| CVE-2026-13260 | Alta (7.5) | 0.43% | — | 14 sept 2026 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources. |
| CVE-2026-13272 | Media (5.4) | 0.15% | — | 14 sept 2026 | IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems. |
| CVE-2026-17616 | Crítica (9.8) | 0.40% | — | 12 ago 2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker… |
| CVE-2026-11932 | Alta (7.5) | 0.46% | — | 12 ago 2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnerable to a denial of service attack. |
| CVE-2026-13267 | Alta (8.1) | 0.35% | — | 12 ago 2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of… |
| CVE-2026-12618 | Alta (7.2) | 0.54% | — | 12 ago 2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional… |
| CVE-2026-12359 | Alta (8.1) | 0.45% | — | 12 ago 2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive… |
| CVE-2026-12005 | Alta (7.2) | 0.54% | — | 12 ago 2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the… |
| CVE-2026-12004 | Alta (8.7) | 0.49% | — | 12 ago 2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the… |
| CVE-2026-11937 | Baja (3.1) | 0.29% | — | 12 ago 2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through… |
| CVE-2026-11923 | Alta (7.4) | 0.32% | — | 12 ago 2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker… |
| CVE-2026-11904 | Media (5.3) | 0.40% | — | 30 jul 2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through… |
| CVE-2026-8861 | Media (5.3) | 0.40% | — | 17 jul 2026 | IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. |
| CVE-2026-7364 | Media (6.1) | 0.36% | — | 17 jul 2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through… |
| CVE-2026-4938 | Media (6.5) | 0.30% | — | 17 jul 2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through… |
| CVE-2026-5926 | Media (6.5) | 0.23% | — | 23 abr 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through… |
| CVE-2026-1346 | Alta (7.8) | 0.23% | — | 8 abr 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through… |
| CVE-2026-1343 | Alta (7.2) | 0.20% | — | 8 abr 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through… |
| CVE-2026-1342 | Alta (7.9) | 0.18% | — | 8 abr 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through… |
| CVE-2026-4364 | Media (5.4) | 0.15% | — | 1 abr 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through… |
| CVE-2026-4101 | Crítica (9.8) | 0.52% | — | 1 abr 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through… |
| CVE-2026-2862 | Media (5.3) | 0.40% | — | 1 abr 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142