CVE-2025-1411
- EPSS 0.01%
- Published 15.06.2025 12:34:16
- Last modified 11.08.2025 18:46:59
IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges.
CVE-2024-51450
- EPSS 0.17%
- Published 06.02.2025 01:15:09
- Last modified 08.08.2025 16:59:06
IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
CVE-2024-45650
- EPSS 0.13%
- Published 31.01.2025 15:15:13
- Last modified 08.08.2025 17:24:38
IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation.
CVE-2022-32754
- EPSS 0.07%
- Published 22.03.2024 16:15:08
- Last modified 21.11.2024 07:06:53
IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within...
CVE-2022-32756
- EPSS 0.04%
- Published 22.03.2024 16:15:08
- Last modified 21.11.2024 07:06:54
IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force...
CVE-2022-32751
- EPSS 0.08%
- Published 22.03.2024 16:15:07
- Last modified 21.11.2024 07:06:53
IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. IBM X-Force ID: 228437.
CVE-2022-32753
- EPSS 0.01%
- Published 22.03.2024 16:15:07
- Last modified 21.11.2024 07:06:53
IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228444.
CVE-2022-32755
- EPSS 0.04%
- Published 14.10.2023 15:15:09
- Last modified 21.11.2024 07:06:53
IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ...
CVE-2022-33161
- EPSS 0.02%
- Published 14.10.2023 15:15:09
- Last modified 21.11.2024 07:07:37
IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information u...