CVE-2025-36355
- EPSS 0.16%
- Veröffentlicht 06.10.2025 16:52:30
- Zuletzt bearbeitet 15.12.2025 19:23:15
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.
CVE-2025-36356
- EPSS 0.18%
- Veröffentlicht 06.10.2025 16:50:48
- Zuletzt bearbeitet 15.12.2025 19:20:17
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required...
CVE-2025-0163
- EPSS 0.29%
- Veröffentlicht 11.06.2025 14:20:28
- Zuletzt bearbeitet 13.08.2025 14:31:41
IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
CVE-2024-56343
- EPSS 0.3%
- Veröffentlicht 06.06.2025 01:28:38
- Zuletzt bearbeitet 20.08.2025 17:36:56
IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a specially crafted POST request.
CVE-2024-56342
- EPSS 0.27%
- Veröffentlicht 06.06.2025 01:27:08
- Zuletzt bearbeitet 20.08.2025 17:38:33
IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the syst...
CVE-2025-0161
- EPSS 0.24%
- Veröffentlicht 20.02.2025 16:15:36
- Zuletzt bearbeitet 08.08.2025 19:42:26
IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local user to execute arbitrary code due to improper restrictions on code generation.
CVE-2024-49814
- EPSS 0.23%
- Veröffentlicht 06.02.2025 01:15:08
- Zuletzt bearbeitet 08.08.2025 17:02:50
IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges.
CVE-2024-35138
- EPSS 0.2%
- Veröffentlicht 04.02.2025 21:15:26
- Zuletzt bearbeitet 18.06.2025 15:32:51
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CVE-2024-40700
- EPSS 0.3%
- Veröffentlicht 04.02.2025 21:15:26
- Zuletzt bearbeitet 15.12.2025 20:01:49
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended function...
CVE-2024-43187
- EPSS 0.24%
- Veröffentlicht 04.02.2025 21:15:26
- Zuletzt bearbeitet 15.12.2025 20:04:28
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.