IBM / Security Directory Server
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-28772 | IBM Security Directory Integrator cross-site scripting | MEDIUM | 6.8 | Jul 25, 2024 |
| CVE-2022-32759 | IBM Security Directory Server information disclosure | HIGH | 7.5 | Jul 25, 2024 |
| CVE-2022-32755 | IBM Security Directory Server external entity injection | CRITICAL | 9.1 | Oct 14, 2023 |
| CVE-2022-33165 | IBM Security Directory Server information disclosure | HIGH | 7.5 | Oct 14, 2023 |
| CVE-2022-33161 | IBM Security Directory Server information disclosure | MEDIUM | 5.9 | Oct 14, 2023 |
| CVE-2022-33164 | IBM Security Directory Server path traversal | CRITICAL | 9.1 | Sep 8, 2023 |
| CVE-2019-4563 | IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie value… | MEDIUM | 5.3 | Oct 29, 2020 |
| CVE-2019-4547 | IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Forc… | MEDIUM | 5.3 | Oct 29, 2020 |
| CVE-2019-4562 | IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the UR… | MEDIUM | 5.3 | Feb 4, 2020 |
| CVE-2019-4551 | IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protec… | MEDIUM | 5.3 | Feb 4, 2020 |
| CVE-2019-4550 | IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952. | MEDIUM | 5.3 | Feb 4, 2020 |
| CVE-2019-4548 | IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web… | MEDIUM | 6.1 | Feb 4, 2020 |
| CVE-2019-4541 | IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct… | HIGH | 7.2 | Feb 4, 2020 |
| CVE-2019-4540 | IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IB… | HIGH | 7.5 | Feb 4, 2020 |
| CVE-2019-4549 | IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.… | MEDIUM | 5.3 | Oct 2, 2019 |
| CVE-2019-4542 | IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu… | MEDIUM | 6.1 | Oct 2, 2019 |
| CVE-2019-4539 | IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or co… | HIGH | 7.1 | Oct 2, 2019 |
| CVE-2019-4538 | IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a… | HIGH | 8.2 | Oct 2, 2019 |
| CVE-2019-4520 | IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-For… | HIGH | 7.5 | Oct 2, 2019 |
| CVE-2015-1976 | IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash. | MEDIUM | 5.5 | Feb 8, 2017 |
| CVE-2015-1977 | Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before 6.2.0.50-I… | HIGH | 7.5 | Jul 15, 2016 |
| CVE-2014-6100 | Cross-site scripting (XSS) vulnerability in the Admin UI in IBM Tivoli Directory Server 6.1 before 6.1.0.64-ISS-ITDS-IF0064, 6.2 before 6.2.0.39-ISS-ITDS-FP003… | LOW | 3.5 | Oct 19, 2014 |
| CVE-2013-6747 | IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows remote attack… | HIGH | 7.1 | Jan 27, 2014 |
Showing 1 to 22 of 22 CVEs