Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In January 2022
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 209515.
CVSS Score
2.7
EPSS Score
0.001
Published
2022-01-10
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209563.
CVSS Score
3.0
EPSS Score
0.003
Published
2022-01-10
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210067.
CVSS Score
5.9
EPSS Score
0.001
Published
2022-01-10
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive version information in HTTP response headers that could aid in further attacks against the system. IBM X-Force ID: 212038
CVSS Score
5.3
EPSS Score
0.001
Published
2022-01-10
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.
CVSS Score
3.1
EPSS Score
0.002
Published
2022-01-10
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to code execution. IBM X-Force ID: 212952.
CVSS Score
8.4
EPSS Score
0.001
Published
2022-01-10
There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.
CVSS Score
9.8
EPSS Score
0.003
Published
2022-01-10
There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this vulnerability may cause memory overflow.
CVSS Score
9.8
EPSS Score
0.002
Published
2022-01-10
There is Vulnerability of APIs being concurrently called for multiple times in HwConnectivityExService a in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-01-10
The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.
CVSS Score
8.8
EPSS Score
0.0
Published
2022-01-10


Contact Us

Shodan ® - All rights reserved