CVE-2026-78407
- EPSS -
- Veröffentlicht 08.10.2026 21:18:03
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering...
CVE-2026-78406
- EPSS -
- Veröffentlicht 08.10.2026 21:18:03
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
CVE-2026-78401
- EPSS -
- Veröffentlicht 08.10.2026 21:18:03
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
CVE-2026-78399
- EPSS -
- Veröffentlicht 08.10.2026 21:18:02
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow an authenticated user to cause a denial of service using a specially crafted HTTP query due to improper allocation of system resources
CVE-2026-78388
- EPSS -
- Veröffentlicht 08.10.2026 21:18:02
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that t...
CVE-2026-19878
- EPSS -
- Veröffentlicht 08.10.2026 21:17:57
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass additional authentication workflow steps.
CVE-2026-19498
- EPSS -
- Veröffentlicht 08.10.2026 21:17:57
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
CVE-2026-19494
- EPSS -
- Veröffentlicht 08.10.2026 21:17:57
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.
CVE-2026-19493
- EPSS -
- Veröffentlicht 08.10.2026 21:17:57
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.
CVE-2026-19491
- EPSS -
- Veröffentlicht 08.10.2026 21:17:57
- Zuletzt bearbeitet 08.10.2026 21:26:32
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication.