Latest CVE Feed
-
6.1
MEDIUMCVE-2022-22477
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit... Read more
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-22476
IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing by an authenticated user using a specially crafted request. IBM X-Force ID: 225604.... Read more
- Published: Jul. 08, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-22475
IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing by an authenticated user. IBM X-Force ID: 225603.... Read more
- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-22474
IBM Spectrum Protect 8.1.0.0 through 8.1.14.0 dsmcad, dsmc, and dsmcsvc processes incorrectly handle certain read operations on TCP/IP sockets. This can result in a denial of service for IBM Spectrum Protect client operations. IBM X-Force ID: 225348.... Read more
Affected Products : spectrum_protect_client- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-22473
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-F... Read more
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-22472
IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, c... Read more
Affected Products : linux_kernel spectrum_protect_plus spectrum_protect_plus_container_backup_and_restore- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-22470
IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225232. ... Read more
Affected Products : security_verify_governance- Published: Jan. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-22466
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:... Read more
Affected Products : security_verify_governance- Published: Oct. 23, 2023
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-22465
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local user to obtain elevated privileges due to improper access permissions. IBM X-Force ID: 225082.... Read more
Affected Products : security_verify_access- Published: Jul. 08, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-22464
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.... Read more
Affected Products : security_verify_access- Published: Jul. 08, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-22463
IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in th... Read more
Affected Products : security_verify_access- Published: Jul. 08, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-22462
IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225078. ... Read more
- Published: Jan. 26, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-22461
IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225007. ... Read more
- Published: Dec. 22, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-22460
IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013.... Read more
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-22458
IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user. IBM X-Force ID: 225009. ... Read more
- Published: Dec. 22, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-22457
IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007.... Read more
- Published: Dec. 22, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-22456
IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials di... Read more
- Published: Dec. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-22455
IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM... Read more
Affected Products : security_verify_governance- Published: Aug. 17, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-22454
IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.... Read more
Affected Products : linux_kernel aix infosphere_information_server windows infosphere_information_server_on_cloud- Published: May. 10, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-22453
IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.... Read more
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024