CVE-2022-43891 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2022-43891
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454. IBM Security Verify Privilege On-Premises 11.5 podría permitir a un atacante remoto obtener información confidencial cuando se devuelve un mensaje de error técnico detallado en el navegador. Esta información podría usarse en futuros ataques contra el System. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240454 https://www.ibm.com/support/pages/node/7047202 • CWE-209: Generation of Error Message Containing Sensitive Information •
CVE-2022-43892 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2022-43892
IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information which could aid further attacks against the system. IBM X-Force ID: 240455. IBM Security Verify Privilege On-Premises 11.5 no valida, o valida incorrectamente, un certificado que podría revelar información confidencial que podría contribuir a futuros ataques contra el System. ID de IBM X-Force: 240455. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240455 https://www.ibm.com/support/pages/node/7047202 • CWE-295: Improper Certificate Validation •
CVE-2022-43889 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2022-43889
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240452. IBM Security Verify Privilege On-Premises 11.5 podría revelar información confidencial a través de una solicitud HTTP que podría ayudar a un atacante en futuros ataques contra el System. ID de IBM X-Force: 240452. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240452 https://www.ibm.com/support/pages/node/7047202 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2021-20581 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2021-20581
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324. IBM Security Verify Privilege On-Premises 11.5 podría permitir a un usuario obtener información confidencial debido a una expiración insuficiente de la sesión. ID de IBM X-Force: 199324. • https://exchange.xforce.ibmcloud.com/vulnerabilities/199324 https://www.ibm.com/support/pages/node/7047202 • CWE-613: Insufficient Session Expiration •
CVE-2021-38859 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2021-38859
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that could be used in further attacks against the system. IBM X-Force ID: 207899. IBM Security Verify Privilege On-Premises 11.5 podría permitir a un usuario obtener información del número de versión mediante una solicitud HTTP especialmente manipulada que podría usarse en futuros ataques contra el System. ID de IBM X-Force: 207899. • https://exchange.xforce.ibmcloud.com/vulnerabilities/207899 https://www.ibm.com/support/pages/node/7047202 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •