CVE-2021-20576
https://notcve.org/view.php?id=CVE-2021-20576
IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash. IBM Security Verify Access versión 20.07, podría permitir a un atacante remoto enviar una petición HTTP GET especialmente diseñada que podría causar que la aplicación se bloquee • https://exchange.xforce.ibmcloud.com/vulnerabilities/199280 https://www.ibm.com/support/pages/node/6457315 •
CVE-2021-20575
https://notcve.org/view.php?id=CVE-2021-20575
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278. IBM Security Verify Access versión 20.07, permite que las páginas web sean almacenadas localmente, que pueden ser leídas por otro usuario en el sistema. X-Force ID: 199278 • https://exchange.xforce.ibmcloud.com/vulnerabilities/199278 https://www.ibm.com/support/pages/node/6457315 • CWE-922: Insecure Storage of Sensitive Information •
CVE-2020-4499
https://notcve.org/view.php?id=CVE-2020-4499
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216. IBM Security Access Manager versión 9.0.7 e IBM Security Verify Access versión 10.0.0, podrían permitir a un cliente Oauth público no autorizado omitir algunas o todas las comprobaciones de autenticación y conseguir acceso a las aplicaciones. IBM X-Force ID: 182216 • https://exchange.xforce.ibmcloud.com/vulnerabilities/182216 https://www.ibm.com/support/pages/node/6348046 •
CVE-2019-4552
https://notcve.org/view.php?id=CVE-2019-4552
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 165960. IBM Security Access Manager versión 9.0.7 e IBM Security Verify Access versión 10.0.0, son vulnerables a unos ataques de división de respuesta HTTP. • https://exchange.xforce.ibmcloud.com/vulnerabilities/165960 https://www.ibm.com/support/pages/node/6348046 •
CVE-2020-4699
https://notcve.org/view.php?id=CVE-2020-4699
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186947. IBM Security Access Manager versión 9.0.7 e IBM Security Verify Access versión 10.0.0, podrían permitir a un atacante obtener información confidencial usando ataques de canal lateral de sincronización que podrían ayudar en futuros ataques contra el sistema. IBM X-Force ID: 186947 • https://exchange.xforce.ibmcloud.com/vulnerabilities/186947 https://www.ibm.com/support/pages/node/6346619 • CWE-203: Observable Discrepancy •