Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2022-22472

    IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, c... Read more

    • Published: Jun. 30, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-22470

    IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225232. ... Read more

    Affected Products : security_verify_governance
    • Published: Jan. 09, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-22466

    IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:... Read more

    Affected Products : security_verify_governance
    • Published: Oct. 23, 2023
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-22465

    IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local user to obtain elevated privileges due to improper access permissions. IBM X-Force ID: 225082.... Read more

    Affected Products : security_verify_access
    • Published: Jul. 08, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-22464

    IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.... Read more

    Affected Products : security_verify_access
    • Published: Jul. 08, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-22463

    IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in th... Read more

    Affected Products : security_verify_access
    • Published: Jul. 08, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-22462

    IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225078. ... Read more

    • Published: Jan. 26, 2023
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-22461

    IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225007. ... Read more

    • Published: Dec. 22, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-22460

    IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be used in further attacks against the system. IBM X-Force ID: 225013.... Read more

    • Published: Jul. 14, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-22458

    IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user. IBM X-Force ID: 225009. ... Read more

    • Published: Dec. 22, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2022-22457

    IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 225007.... Read more

    • Published: Dec. 22, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2022-22456

    IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials di... Read more

    • Published: Dec. 22, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-22455

    IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM... Read more

    Affected Products : security_verify_governance
    • Published: Aug. 17, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-22454

    IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.... Read more

    • Published: May. 10, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-22453

    IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 224919.... Read more

    • Published: Jul. 14, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-22452

    IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918.... Read more

    • Published: Jul. 14, 2022
    • Modified: Nov. 21, 2024
  • 3.8

    LOW
    CVE-2022-22450

    IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916.... Read more

    • Published: Jul. 14, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2022-22449

    IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.... Read more

    • Published: Dec. 24, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2022-22447

    IBM Disconnected Log Collector 1.0 through 1.8.2 is vulnerable to potential security misconfigurations that could disclose unintended information. IBM X-Force ID: 224648.... Read more

    Affected Products : disconnected_log_collector
    • Published: Oct. 04, 2023
    • Modified: Nov. 21, 2024
  • 7.6

    HIGH
    CVE-2022-22445

    An attacker that gains service access to the FSP (POWER9 only) or gains admin authority to a partition can compromise partition firmware.... Read more

    Affected Products : powervm_hypervisor
    • Published: Jul. 18, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294863 Results