CVE-2022-22453
https://notcve.org/view.php?id=CVE-2022-22453
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919. IBM Security Verify Identity Manager versión 10.0, usa algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. IBM X-Force ID: 224919 • https://exchange.xforce.ibmcloud.com/vulnerabilities/224919 https://www.ibm.com/support/pages/node/6603405 • CWE-326: Inadequate Encryption Strength •
CVE-2022-22452
https://notcve.org/view.php?id=CVE-2022-22452
IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918. IBM Security Verify Identity Manager versión 10.0, usa una configuración de bloqueo de cuentas inapropiada que podría permitir a un atacante remoto forzar las credenciales de las cuentas. IBM X-Force ID: 224918 • https://exchange.xforce.ibmcloud.com/vulnerabilities/224918 https://www.ibm.com/support/pages/node/6603405 • CWE-307: Improper Restriction of Excessive Authentication Attempts •
CVE-2022-22450
https://notcve.org/view.php?id=CVE-2022-22450
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916. IBM Security Verify Identity Manager versión 10.0, podría permitir a un usuario privilegiado cargar un archivo malicioso al omitir la seguridad de la extensión en una petición HTTP. IBM X-Force ID: 224916 • https://exchange.xforce.ibmcloud.com/vulnerabilities/224916 https://www.ibm.com/support/pages/node/6603405 • CWE-434: Unrestricted Upload of File with Dangerous Type •