CVE-2023-33836 – IBM Security Verify Governance information disclosure
https://notcve.org/view.php?id=CVE-2023-33836
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 256016. IBM Security Verify Governance 10.0 contiene credenciales codificadas, como una contraseña o clave criptográfica, que utiliza para su propia autenticación entrante, comunicación saliente con componentes externos o cifrado de datos internos. ID de IBM X-Force: 256016. • https://https://exchange.xforce.ibmcloud.com/vulnerabilities/256016 https://www.ibm.com/support/pages/node/7047640 • CWE-798: Use of Hard-coded Credentials •
CVE-2023-35013 – IBM Security Verify Governance information disclosure
https://notcve.org/view.php?id=CVE-2023-35013
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769. IBM Security Verify Governance 10.0, Identity Manager podría permitir que un usuario privilegiado local obtenga información confidencial del código fuente. ID de IBM X-Force: 257769. • https://exchange.xforce.ibmcloud.com/vulnerabilities/257769 https://www.ibm.com/support/pages/node/7050358 • CWE-540: Inclusion of Sensitive Information in Source Code CWE-668: Exposure of Resource to Wrong Sphere •
CVE-2023-30994 – IBM QRadar SIEM information disclosure
https://notcve.org/view.php?id=CVE-2023-30994
IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 254138 IBM QRadar SIEM 7.5.0 utiliza algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. IBM X-Force ID: 254138 • https://exchange.xforce.ibmcloud.com/vulnerabilities/254138 https://www.ibm.com/support/pages/node/7049133 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2022-43868 – IBM Security Verify Access information disclosure
https://notcve.org/view.php?id=CVE-2022-43868
IBM Security Verify Access OIDC Provider could disclose directory information that could aid attackers in further attacks against the system. IBM X-Force ID: 239445. IBM Security Verify Access OIDC Provider podría revelar información de directorio que podría ayudar a los atacantes en futuros ataques contra el sistema. ID de IBM X-Force: 239445. • https://exchange.xforce.ibmcloud.com/vulnerabilities/239445 https://www.ibm.com/support/pages/node/7028513 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2022-33165 – IBM Security Directory Server information disclosure
https://notcve.org/view.php?id=CVE-2022-33165
IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 228582. IBM Security Directory Server 6.4.0 podría permitir que un atacante remoto atraviese directorios del sistema. Un atacante podría enviar una solicitud URL especialmente manipulada que contenga secuencias de "puntos" (/../) para ver archivos arbitrarios en el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/228582 https://www.ibm.com/support/pages/node/7047116 https://www.ibm.com/support/pages/node/7047428 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •