📦 Security Verify Access

by Ibm

🔍 What is Security Verify Access?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-36356

CRITICAL CVSS 9.3 Oct 6, 2025

This vulnerability allows a locally authenticated user on affected IBM Security Verify Access systems to escalate their privileges to root due to improper privilege management. The flaw exists because...

CVE-2024-49803

CRITICAL CVSS 9.8 Nov 29, 2024

This vulnerability allows remote authenticated attackers to execute arbitrary commands on IBM Security Verify Access Appliances. Attackers can achieve full system compromise by sending specially craft...

CVE-2024-49805

CRITICAL CVSS 9.4 Nov 29, 2024

IBM Security Verify Access Appliance versions 10.0.0 through 10.0.8 contain hard-coded credentials that could allow attackers to authenticate to the system, communicate with external components, or de...

CVE-2021-39070

CRITICAL CVSS 9.8 Feb 2, 2022

This critical authentication bypass vulnerability in IBM Security Verify Access allows an attacker to authenticate as any user on the system when the advanced access control authentication service is ...

CVE-2020-4499

CRITICAL CVSS 9.8 Oct 15, 2020

This vulnerability allows unauthorized OAuth clients to bypass authentication checks in IBM Security Access Manager and IBM Security Verify Access. Attackers could gain unauthorized access to protecte...

CVE-2025-36354

HIGH CVSS 7.3 Oct 6, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary commands with limited privileges on IBM Security Verify Access systems. It affects IBM Security Verify Access and IBM Security ...

CVE-2025-0161

HIGH CVSS 7.8 Feb 20, 2025

This vulnerability in IBM Security Verify Access Appliance allows local users to execute arbitrary code due to improper restrictions on code generation. It affects versions 10.0.0.0 through 10.0.0.9 a...

CVE-2024-31872

HIGH CVSS 7.5 Apr 10, 2024

IBM Security Verify Access Appliance versions 10.0.0 through 10.0.7 have a missing certificate validation vulnerability when deploying Open Source scripts. This allows attackers to conduct man-in-the-...

CVE-2024-28787

HIGH CVSS 8.7 Apr 4, 2024

This vulnerability in IBM Security Verify Access and IBM Application Gateway allows remote attackers to obtain sensitive information or cause denial of service via specially crafted HTTP requests. It ...

CVE-2023-43017

HIGH CVSS 8.2 Feb 7, 2024

This vulnerability in IBM Security Verify Access allows a privileged user to install a configuration file that could enable remote access, potentially leading to unauthorized control or data exposure....

CVE-2023-32328

HIGH CVSS 7.5 Feb 7, 2024

IBM Security Verify Access versions 10.0.0.0 through 10.0.6.1 use insecure protocols in some instances, allowing attackers on the same network to potentially take control of the server. This affects o...

CVE-2023-43016

HIGH CVSS 7.3 Feb 3, 2024

This vulnerability allows remote attackers to log into IBM Security Access Manager servers using a user account with an empty password. It affects IBM Security Verify Access Appliance and Docker conta...

CVE-2023-32327

HIGH CVSS 7.1 Feb 3, 2024

This CVE describes an XML External Entity (XXE) vulnerability in IBM Security Access Manager Container products. Attackers can exploit this by submitting malicious XML data to read sensitive files or ...

CVE-2023-30999

HIGH CVSS 7.5 Feb 3, 2024

This vulnerability in IBM Security Access Manager Container allows attackers to cause denial of service through uncontrolled resource consumption. It affects IBM Security Verify Access Appliance and D...

CVE-2023-31003

HIGH CVSS 8.4 Jan 11, 2024

This vulnerability allows a local user on IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0-10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) to escalate priv...

CVE-2022-22464

HIGH CVSS 7.5 Jul 8, 2022

IBM Security Access Manager Appliance uses weak cryptographic algorithms that could allow attackers to decrypt sensitive information. This affects IBM Security Access Manager Appliance versions 10.0.0...

CVE-2021-38921

HIGH CVSS 7.5 Jan 10, 2022

IBM Security Verify versions 10.0.0 through 10.0.2.0 use weak cryptographic algorithms, allowing attackers to decrypt sensitive information stored or transmitted by the system. This affects organizati...

CVE-2021-38957

HIGH CVSS 7.5 Jan 10, 2022

IBM Security Verify versions 10.0.0 through 10.0.2.0 contain an input validation vulnerability during QR code generation that could allow attackers to disclose sensitive information. This affects orga...

CVE-2021-20533

HIGH CVSS 7.2 Jul 15, 2021

CVE-2021-20533 allows a remote authenticated attacker to execute arbitrary commands on IBM Security Verify Access Docker 10.0.0 systems by sending a specially crafted request. This affects organizatio...

CVE-2021-29742

HIGH CVSS 8.0 Jul 15, 2021

CVE-2021-29742 is an authentication bypass vulnerability in IBM Security Verify Access Docker 10.0.0 that allows an authenticated user to impersonate another user on the system. This affects organizat...

CVE-2021-20497

HIGH CVSS 7.5 Jul 15, 2021

IBM Security Verify Access Docker 10.0.0 uses weak cryptographic algorithms that could allow attackers to decrypt sensitive information. This affects organizations using this specific IBM containerize...

CVE-2021-20439

HIGH CVSS 7.5 Jul 15, 2021

IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 store user credentials in plain text, allowing unauthorized users to read sensitive authentication data. This affects organ...

CVE-2021-20576

HIGH CVSS 7.5 Jun 1, 2021

CVE-2021-20576 is a denial-of-service vulnerability in IBM Security Verify Access 20.07 where a remote attacker can send a specially crafted HTTP GET request to crash the application. This affects org...

CVE-2024-35138

MEDIUM CVSS 6.5 Feb 4, 2025

IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8 contain a cross-site request forgery (CSRF) vulnerability. This allows attackers to trick authenticated users into per...

CVE-2024-43187

MEDIUM CVSS 5.9 Feb 4, 2025

IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8 transmit sensitive data in cleartext over network channels, allowing unauthorized actors to intercept and read securit...

CVE-2024-45647

MEDIUM CVSS 5.6 Jan 20, 2025

This vulnerability in IBM Security Verify Access allows unauthenticated attackers to reset passwords for expired user accounts without knowing the current password. It affects IBM Security Verify Acce...

CVE-2024-28772

MEDIUM CVSS 6.8 Jul 25, 2024

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 contain a stored cross-site scripting (XSS) vulnerability that allows authenticated users to inject maliciou...

CVE-2024-31883

MEDIUM CVSS 5.3 Jun 27, 2024

IBM Security Verify Access versions 10.0.0.0 through 10.0.7.1, under certain configurations, are vulnerable to asymmetric resource consumption denial-of-service attacks. Unauthenticated attackers can ...

CVE-2023-30430

MEDIUM CVSS 5.5 Jun 27, 2024

This vulnerability in IBM Security Verify Access allows local users to access sensitive information from trace logs. It affects versions 10.0.0 through 10.0.7.1. The exposure could include credentials...