CVE-2026-11930
- EPSS -
- Veröffentlicht 08.10.2026 21:17:54
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 may not enforce authorization correctly for some web servers.
CVE-2026-11888
- EPSS -
- Veröffentlicht 08.10.2026 21:17:54
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to an information disclosure attack.
CVE-2026-11921
- EPSS 0.13%
- Veröffentlicht 15.09.2026 17:27:11
- Zuletzt bearbeitet 17.09.2026 17:16:38
IBM Verify Identity Access containers may not apply management password change operations correctly.
CVE-2026-11926
- EPSS 0.31%
- Veröffentlicht 15.09.2026 17:21:22
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
CVE-2026-11927
- EPSS 0.15%
- Veröffentlicht 15.09.2026 17:20:42
- Zuletzt bearbeitet 20.09.2026 01:16:27
IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.
CVE-2026-11928
- EPSS 0.14%
- Veröffentlicht 15.09.2026 17:19:48
- Zuletzt bearbeitet 17.09.2026 17:16:38
IBM Verify Identity Access is vulnerable to a buffer overflow attack.
CVE-2026-11929
- EPSS 0.16%
- Veröffentlicht 15.09.2026 17:18:57
- Zuletzt bearbeitet 16.09.2026 19:21:55
IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
CVE-2026-11934
- EPSS 0.32%
- Veröffentlicht 15.09.2026 17:17:02
- Zuletzt bearbeitet 16.09.2026 19:21:55
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
CVE-2026-12101
- EPSS 0.14%
- Veröffentlicht 15.09.2026 17:16:19
- Zuletzt bearbeitet 20.09.2026 01:16:27
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.
CVE-2026-12358
- EPSS 0.39%
- Veröffentlicht 15.09.2026 17:12:16
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.