Security Directory Integrator
Vendor:
First CVE: Oct 14, 2023 · Active for 2 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Security Directory Integrator over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 14, 2023
2 years ago
Most Recent CVE
May 27, 2026
59 days ago
CVE Severity & Scoring
Security Directory Integrator11 CVEs
45%
45%
9%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None8 (72.7%)
Unknown0 (0.0%)
Required3 (27.3%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None9 (81.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-33162CRITICAL IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity | Aug 16, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-28767HIGH IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sendin | Dec 20, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-32759HIGH IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain se | Jul 25, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-28765MEDIUM IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed techn | May 27, 2026 | 5.3 | 21 | NO | NO |
CVE-2024-28766HIGH IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further | Jan 27, 2025 | 7.5 | 21 | NO | NO |
CVE-2022-33167HIGH IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to | Jul 30, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-28771MEDIUM IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers | Jan 27, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-28770MEDIUM IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers | Jan 27, 2025 | 6.5 | 19 | NO | NO |
CVE-2022-33165HIGH IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" | Oct 14, 2023 | 7.5 | 19 | NO | NO |
CVE-2022-33161MEDIUM IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attac | Oct 14, 2023 | 5.9 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Security Directory Integrator
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.2.0 | 9 | 7.1 | 0.4% | 0 | 0 |