Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-15729
HistoryMar 26, 2024 - 12:00 a.m.

IBM Security Verify Directory Cross-Site Scripting Vulnerability

2024-03-2600:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
ibm
security verify directory
cross-site scripting
vulnerability
authentication
access management
international business machines
credential disclosure

6.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.1%

IBM Security Verify Directory is part of an authentication and access management solution from International Business Machines (IBM). A cross-site scripting vulnerability exists in IBM Security Verify Directory version 10.0.0, which originates from a vulnerability that allows a user to embed arbitrary JavaScript code in the Web UI, which could change the intended functionality and lead to credential disclosure in a trusted session. No details of the vulnerability are available at this time.

CPENameOperatorVersion
ibm security verify directoryeq10.0.0

6.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.1%

Related for CNVD-2024-15729