CVE-2023-31002 – IBM Security Access Manager Container information disclosure
https://notcve.org/view.php?id=CVE-2023-31002
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657. IBM Security Access Manager Container 10.0.0.0 a 10.0.6.1 almacena temporalmente información confidencial en archivos a los que podría acceder un usuario local. ID de IBM X-Force: 254657. • https://exchange.xforce.ibmcloud.com/vulnerabilities/254657 https://www.ibm.com/support/pages/node/7106586 • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2023-43017 – IBM Security Verify Access man in the middle
https://notcve.org/view.php?id=CVE-2023-43017
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155. IBM Security Verify Access 10.0.0.0 a 10.0.6.1 podría permitir a un usuario privilegiado instalar un archivo de configuración que podría permitir el acceso remoto. ID de IBM X-Force: 266155. • https://exchange.xforce.ibmcloud.com/vulnerabilities/266155 https://www.ibm.com/support/pages/node/7106586 • CWE-295: Improper Certificate Validation •
CVE-2023-32330 – IBM Security Verify Access man in the middle
https://notcve.org/view.php?id=CVE-2023-32330
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977. IBM Security Verify Access 10.0.0.0 a 10.0.6.1 utiliza llamadas inseguras que podrían permitir que un atacante en la red tome el control del servidor. ID de IBM X-Force: 254977. IBM Security Verify Access versions prior to 10.0.8 suffer from authentication bypass, reuse of private keys, local privilege escalation, weak settings, outdated libraries, missing password, hardcoded secrets, remote code execution, missing authentication, null pointer dereference, and lack of privilege separation vulnerabilities. • https://exchange.xforce.ibmcloud.com/vulnerabilities/254977 https://www.ibm.com/support/pages/node/7106586 • CWE-295: Improper Certificate Validation •
CVE-2023-32328 – IBM Security Verify Access information disclosure
https://notcve.org/view.php?id=CVE-2023-32328
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957. IBM Security Verify Access 10.0.0.0 a 10.0.6.1 utiliza protocolos inseguros en algunos casos que podrían permitir que un atacante en la red tome el control del servidor. Identificación de IBM X-Force: 254957. IBM Security Verify Access versions prior to 10.0.8 suffer from authentication bypass, reuse of private keys, local privilege escalation, weak settings, outdated libraries, missing password, hardcoded secrets, remote code execution, missing authentication, null pointer dereference, and lack of privilege separation vulnerabilities. • https://exchange.xforce.ibmcloud.com/vulnerabilities/254657 https://www.ibm.com/support/pages/node/7106586 • CWE-319: Cleartext Transmission of Sensitive Information •
CVE-2024-22331 – IBM UrbanCode Deploy information disclosure
https://notcve.org/view.php?id=CVE-2024-22331
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy 8.0.0.0 could disclose sensitive user information when installing the Windows agent. IBM X-Force ID: 279971. IBM UrbanCode Deploy (UCD) 7.0 a 7.0.5.19, 7.1 a 7.1.2.15, 7.2 a 7.2.3.8, 7.3 a 7.3.2.3 e IBM UrbanCode Deploy (UCD): IBM DevOps Deploy 8.0.0.0 podría revelar información confidencial del usuario cuando instalar el agente de Windows. ID de IBM X-Force: 279971. • https://exchange.xforce.ibmcloud.com/vulnerabilities/279971 https://www.ibm.com/support/pages/node/7114131 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •