Skip to main content

Vendor/product archive

ibm / verify_gateway CVEs

Beta · best-effort

8 CVEs tagged to ibm / verify_gateway1 Critical, 2 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2020-4405

Published Jul 27, 2020

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could disclose potentially sensitive information to an authenticated user due to world readable log files. IBM X-Force ID: 179484.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4400

Published Jul 22, 2020

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-4399

Published Jul 22, 2020

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 could allow an authenticated user to send malformed requests to cause a denial of service against the server. IBM X-Force ID: 179476.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4397

Published Jul 22, 2020

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 transmits sensitive information in plain text which could be obtained by an attacker using man in the middle techniques. IBM X-Force ID: 1…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4385

Published Jul 22, 2020

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound commu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-4372

Published Jul 22, 2020

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4371

Published Jul 22, 2020

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains sensitive information in leftover debug code that could be used aid a local user in further attacks against the system. IBM X-For…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-4369

Published Jul 22, 2020

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a user. IBM X-Force ID: 179004.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1