Known vulnerabilities in IBM Security Verify Access - page 6

Software CPE: cpe:2.3:a:ibm_corporation:security_access_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 224
Public exploits: 15
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Security Verify Access IBM Security Verify Access is affected by 224 known vulnerabilities: 28 high, 133 medium, 63 low Critical High Medium Low

Vulnerabilities (224)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU82350 - Resource Management Errors
CVE-2023-46158
CWE-399 Medium
No
No
10.0.7.0 24.10.2023 SB2023102444
SB2023120144
SB2023122104
and 30 more
#VU79767 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-40225
CWE-444 Medium
No
No
10.0.7.0 21.08.2023 SB2023082120
SB2023082121
SB2023082122
and 17 more
#VU79519 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-32697
CWE-94 High
No
No
10.0.7.0 15.08.2023 SB2023090805
SB2023090807
SB2023091411
and 7 more
#VU79454 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-39417
CWE-89 Medium
No
No
10.0.7.0 11.08.2023 SB2023081132
SB2023081715
SB2023081716
and 60 more
#VU77102 - Stack-based buffer overflow
CVE-2022-45688
CWE-121 Medium
No
No
10.0.7.0 08.06.2023 SB2023060836
SB2023060927
SB2023071959
and 35 more
#VU76042 - Security Features
CVE-2023-2455
CWE-254 Low
No
No
10.0.7.0 11.05.2023 SB2023051138
SB2023051301
SB2023051528
and 61 more
#VU76041 - Permissions, Privileges, and Access Controls
CVE-2023-2454
CWE-264 Medium
No
No
10.0.7.0 11.05.2023 SB2023051138
SB2023051301
SB2023051528
and 55 more
#VU75044 - Uncontrolled Recursion
CVE-2023-1370
CWE-674 Medium
No
No
10.0.7.0 12.04.2023 SB2023041258
SB2023041259
SB2023041809
and 130 more
#VU72413 - Out-of-bounds write
CVE-2023-24988
CWE-787 High
No
No
10.0.7.0 20.02.2023 SB2023022034
SB2024010808
#VU72334 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-25725
CWE-444 Medium
No
No
10.0.7.0 16.02.2023 SB2023021659
SB2023021662
SB2023021663
and 22 more
#VU72088 - Out-of-bounds read
CVE-2022-41862
CWE-125 Medium
No
No
10.0.7.0 09.02.2023 SB2023020953
SB2023021334
SB2023021335
and 47 more
#VU70385 - Deserialization of Untrusted Data
CVE-2022-1471
CWE-502 High
Available
No
10.0.7.0 15.12.2022 SB2022121539
SB2022121540
SB2022121928
and 124 more
#VU70097 - Heap-based Buffer Overflow
CVE-2015-5237
CWE-122 High
No
No
10.0.7.0 10.12.2022 SB2017092512
SB2023011801
SB2023042744
and 7 more
#VU66429 - Permissions, Privileges, and Access Controls
CVE-2022-2625
CWE-264 Low
No
No
10.0.7.0 12.08.2022 SB2022081212
SB2022081848
SB2022082547
and 40 more
#VU26549 - Heap-based Buffer Overflow
CVE-2020-11100
CWE-122 High
No
No
10.0.7.0 02.04.2020 SB2020040219
SB2020040220
SB2020040221
and 13 more
#VU24690 - Improper Check for Dropped Privileges
CVE-2019-18276
CWE-273 Low
Available
No
10.0.7.0 28.01.2020 SB2019112815
SB2020012803
SB2021052032
and 14 more
#VU23084 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2019-19330
CWE-93 Medium
No
No
10.0.7.0 28.11.2019 SB2019112812
SB2019112813
SB2019120422
and 7 more
#VU22942 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2019-14241
CWE-835 Medium
No
No
10.0.7.0 24.11.2019 SB2019072309
SB2019112403
SB2019112404
and 1 more
#VU22597 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2019-18277
CWE-444 Medium
No
No
10.0.7.0 07.11.2019 SB2019110721
SB2019110722
SB2019120408
and 6 more
#VU21781 - Improper input validation
CVE-2017-18342
CWE-20 High
No
No
10.0.7.0 15.10.2019 SB2018062716
SB2020031928
SB2023080233
and 6 more


Showing elements 101 - 120 out of 224