CVE-2021-20581 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2021-20581
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324. IBM Security Verify Privilege On-Premises 11.5 podría permitir a un usuario obtener información confidencial debido a una expiración insuficiente de la sesión. ID de IBM X-Force: 199324. • https://exchange.xforce.ibmcloud.com/vulnerabilities/199324 https://www.ibm.com/support/pages/node/7047202 • CWE-613: Insufficient Session Expiration •
CVE-2021-38859 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2021-38859
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that could be used in further attacks against the system. IBM X-Force ID: 207899. IBM Security Verify Privilege On-Premises 11.5 podría permitir a un usuario obtener información del número de versión mediante una solicitud HTTP especialmente manipulada que podría usarse en futuros ataques contra el System. ID de IBM X-Force: 207899. • https://exchange.xforce.ibmcloud.com/vulnerabilities/207899 https://www.ibm.com/support/pages/node/7047202 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2022-22385 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2022-22385
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmission of data in clear text. IBM X-Force ID: 221962. IBM Security Verify Privilege On-Premises 11.5 podría revelar información confidencial a un atacante debido a la transmisión de datos en texto plano. ID de IBM X-Force: 221962. • https://exchange.xforce.ibmcloud.com/vulnerabilities/221962 https://www.ibm.com/support/pages/node/7047202 • CWE-319: Cleartext Transmission of Sensitive Information •
CVE-2022-22386 – IBM Security Verify Privilege information disclosure
https://notcve.org/view.php?id=CVE-2022-22386
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 221963. IBM Security Verify Privilege On-Premises 11.5 podría permitir que un atacante remoto obtenga información confidencial, causada por no habilitar correctamente HTTP Strict Transport Security. Un atacante podría aprovechar esta vulnerabilidad para obtener información confidencial utilizando técnicas de intermediario. • https://exchange.xforce.ibmcloud.com/vulnerabilities/221963 https://www.ibm.com/support/pages/node/7047202 • CWE-311: Missing Encryption of Sensitive Data •
CVE-2022-22384 – IBM Security Verify Privilege improper input validation
https://notcve.org/view.php?id=CVE-2022-22384
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due to hazardous input validation. IBM X-Force ID: 221961. IBM Security Verify Privilege On-Premises 11.5 podría permitir a un atacante modificar los mensajes devueltos por el servidor debido a una validación de entrada peligrosa. ID de IBM X-Force: 221961. • https://exchange.xforce.ibmcloud.com/vulnerabilities/221961 https://www.ibm.com/support/pages/node/7047202 • CWE-20: Improper Input Validation •