Skip to main content

Vendor/product archive

ibm / security_directory_server CVEs

Beta · best-effort

22 CVEs tagged to ibm / security_directory_server0 Critical, 8 High, 13 Medium, 1 Low, 0 Unrated.

CVE-2022-33164

Published Sep 8, 2023

IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4563

Published Oct 29, 2020

IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4547

Published Oct 29, 2020

IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 165949.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4562

Published Feb 4, 2020

IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs,…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4551

Published Feb 4, 2020

IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-For…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4550

Published Feb 4, 2020

IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4548

Published Feb 4, 2020

IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attac…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4541

Published Feb 4, 2020

IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the syste…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4540

Published Feb 4, 2020

IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4549

Published Oct 2, 2019

IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 1659…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4542

Published Oct 2, 2019

IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4539

Published Oct 2, 2019

IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML be…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4538

Published Oct 2, 2019

IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted W…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4520

Published Oct 2, 2019

IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 165178.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1