CVE-2022-32752 – IBM Security Directory Suite VA command execution
https://notcve.org/view.php?id=CVE-2022-32752
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 228439. IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 podría permitir a un atacante remoto autenticado ejecutar comandos arbitrarios en el sistema enviando una solicitud especialmente manipulada. ID de IBM X-Force: 228439. • https://exchange.xforce.ibmcloud.com/vulnerabilities/228439 https://www.ibm.com/support/pages/node/7001693 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-32757 – IBM Security Directory Suite VA information disclosure
https://notcve.org/view.php?id=CVE-2022-32757
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 228510. IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 utiliza una configuración de bloqueo de cuentas inadecuada que podría permitir a un atacante remoto forzar las credenciales de las cuentas. ID de IBM X-Force: 228510. • https://exchange.xforce.ibmcloud.com/vulnerabilities/228510 https://www.ibm.com/support/pages/node/7001693 • CWE-307: Improper Restriction of Excessive Authentication Attempts •
CVE-2022-33166 – IBM Security Directory Suite VA file upload
https://notcve.org/view.php?id=CVE-2022-33166
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 228586. IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 podría permitir a un usuario con privilegios cargar archivos maliciosos con formatos peligrosos que pueden procesarse automáticamente en el entorno del producto. ID de IBM X-Force: 228586. • https://exchange.xforce.ibmcloud.com/vulnerabilities/228586 https://www.ibm.com/support/pages/node/7001693 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2022-33159 – IBM Security Directory Suite VA information disclosure
https://notcve.org/view.php?id=CVE-2022-33159
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 228567. IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 almacena las credenciales de usuario en texto sin formato que puede leer un usuario autenticado. ID de IBM X-Force: 228567. • https://exchange.xforce.ibmcloud.com/vulnerabilities/228567 https://www.ibm.com/support/pages/node/7001693 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-312: Cleartext Storage of Sensitive Information •
CVE-2022-33168 – IBM Security Directory Suite VA denial of service
https://notcve.org/view.php?id=CVE-2022-33168
IBM Security Directory Suite VA 8.0.1 could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 228588. IBM Security Directory Suite VA v8.0.1 podría permitir a un atacante provocar una denegación de servicio debido al consumo incontrolado de recursos. ID de IBM X-Force: 228588. • https://exchange.xforce.ibmcloud.com/vulnerabilities/228588 https://www.ibm.com/support/pages/node/7001885 • CWE-400: Uncontrolled Resource Consumption •