Page 3 of 20 results (0.002 seconds)

CVSS: 8.1EPSS: 0%CPEs: 7EXPL: 0

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 127342. IBM Security Identity Governance Virtual Appliance, desde la versión 5.2 hasta la 5.2.3.2, especifica permisos para un recurso crítico para la seguridad de forma que permite que ese recurso sea leído o modificado por actores no planeados. IBM X-Force ID: 127342. • http://www.ibm.com/support/docview.wss?uid=swg22016869 https://exchange.xforce.ibmcloud.com/vulnerabilities/127342 • CWE-275: Permission Issues •

CVSS: 7.5EPSS: 0%CPEs: 7EXPL: 0

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126859. IBM Security Identity Governance Virtual Appliance desde la versión 5.2 hasta la 5.2.3.2 emplea algoritmos criptográficos más débiles de lo esperado que podrían permitir que un atacante descifre información altamente sensible. IBM X-Force ID: 126859. • http://www.ibm.com/support/docview.wss?uid=swg22016869 https://exchange.xforce.ibmcloud.com/vulnerabilities/126859 • CWE-326: Inadequate Encryption Strength •

CVSS: 6.5EPSS: 0%CPEs: 7EXPL: 0

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 126861. IBM Security Identity Governance Virtual Appliance, desde la versión 5.2 hasta la 5.2.3.2, no establece el atributo secure en los tokens de autorización o las cookies de sesión. • http://www.ibm.com/support/docview.wss?uid=swg22016869 https://exchange.xforce.ibmcloud.com/vulnerabilities/126861 • CWE-384: Session Fixation •

CVSS: 5.3EPSS: 0%CPEs: 7EXPL: 0

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 127396. IBM Security Identity Governance y Intelligence Virtual Appliance desde la versión 5.2 hasta la 5.2.3.2 revela información sensible a usuarios no autorizados. Esta información puede emplearse para ejecutar más ataques en el sistema. • http://www.ibm.com/support/docview.wss?uid=swg22016869 https://exchange.xforce.ibmcloud.com/vulnerabilities/127396 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.5EPSS: 0%CPEs: 7EXPL: 0

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 127399. IBM Security Identity Governance Virtual Appliance, desde la versión 5.2 hasta la 5.2.3.2, no requiere que los usuarios tengan contraseñas fuertes por defecto, lo que facilita que los atacantes comprometan las cuentas de usuario. IBM X-Force ID: 127399. • http://www.ibm.com/support/docview.wss?uid=swg22016869 https://exchange.xforce.ibmcloud.com/vulnerabilities/127399 • CWE-522: Insufficiently Protected Credentials •