CVE-2022-43889 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2022-43889
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240452. IBM Security Verify Privilege On-Premises 11.5 podría revelar información confidencial a través de una solicitud HTTP que podría ayudar a un atacante en futuros ataques contra el System. ID de IBM X-Force: 240452. • https://exchange.xforce.ibmcloud.com/vulnerabilities/240452 https://www.ibm.com/support/pages/node/7047202 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2021-29913 – IBM Security Verify Privilege improper input validation
https://notcve.org/view.php?id=CVE-2021-29913
IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 207898. IBM Security Verify Privilege On-Premise 11.5 podría permitir que un usuario autenticado obtenga información confidencial o realice acciones no autorizadas debido a una validación de entrada incorrecta. ID de IBM X-Force: 207898. • https://exchange.xforce.ibmcloud.com/vulnerabilities/207898 https://www.ibm.com/support/pages/node/7047202 • CWE-20: Improper Input Validation •
CVE-2022-22380 – IBM Security Verify Privilege improper authentication
https://notcve.org/view.php?id=CVE-2022-22380
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity due to improperly validating certificates. IBM X-Force ID: 221957. IBM Security Verify Privilege On-Premises 11.5 podría permitir a un atacante falsificar una entidad de confianza debido a una validación incorrecta de los certificados. ID de IBM X-Force: 221957. • https://exchange.xforce.ibmcloud.com/vulnerabilities/221957 https://www.ibm.com/support/pages/node/7047202 • CWE-295: Improper Certificate Validation •
CVE-2022-22375 – IBM Security Verify Privilege command execution
https://notcve.org/view.php?id=CVE-2022-22375
IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681. IBM Security Verify Privilege On-Premises 11.5 podría permitir que un atacante remoto autenticado ejecute comandos arbitrarios en el System enviando una solicitud especialmente manipulada. ID de IBM X-Force: 221681. • https://exchange.xforce.ibmcloud.com/vulnerabilities/221681 https://www.ibm.com/support/pages/node/7047202 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2021-20581 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2021-20581
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324. IBM Security Verify Privilege On-Premises 11.5 podría permitir a un usuario obtener información confidencial debido a una expiración insuficiente de la sesión. ID de IBM X-Force: 199324. • https://exchange.xforce.ibmcloud.com/vulnerabilities/199324 https://www.ibm.com/support/pages/node/7047202 • CWE-613: Insufficient Session Expiration •