Security Directory Server
Vendor:
First CVE: Jan 27, 2014 · Active for 12 years
22
Total CVEs
More Total CVEs than 94% of tracked products
3.1
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Security Directory Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 27, 2014
12 years ago
Most Recent CVE
Jul 25, 2024
729 days ago
CVE Severity & Scoring
Security Directory Server22 CVEs
50%
36%
9%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (4.5%)
Network19 (86.4%)
Unknown2 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (86.4%)
High1 (4.5%)
Unknown2 (9.1%)
User Interaction
None16 (72.7%)
Unknown2 (9.1%)
Required4 (18.2%)
Privileges Required
Low3 (13.6%)
High1 (4.5%)
None16 (72.7%)
Unknown2 (9.1%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-33164CRITICAL IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" | Sep 8, 2023 | 9.1 | 28 | NO | NO |
CVE-2022-32755CRITICAL IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to e | Oct 14, 2023 | 9.1 | 27 | NO | NO |
CVE-2019-4538HIGH IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted We | Oct 2, 2019 | 8.2 | 26 | NO | NO |
CVE-2019-4520HIGH IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 165178. | Oct 2, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-4540HIGH IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813. | Feb 4, 2020 | 7.5 | 23 | NO | NO |
CVE-2022-32759HIGH IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain se | Jul 25, 2024 | 7.5 | 22 | NO | NO |
CVE-2019-4563MEDIUM IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:/ | Oct 29, 2020 | 5.3 | 20 | NO | NO |
CVE-2019-4548MEDIUM IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attack | Feb 4, 2020 | 6.1 | 20 | NO | NO |
CVE-2019-4549MEDIUM IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 16595 | Oct 2, 2019 | 5.3 | 20 | NO | NO |
CVE-2022-33161MEDIUM IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attac | Oct 14, 2023 | 5.9 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Security Directory Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.2.0 | 1 | 9.1 | 1.5% | 0 | 0 |
| 6.4.0.8 | 1 | 7.5 | 1.7% | 0 | 0 |
| 6.4.0.7 | 1 | 7.5 | 1.7% | 0 | 0 |
| 6.4.0.6 | 1 | 7.5 | 1.7% | 0 | 0 |
| 6.4.0.5 | 1 | 7.5 | 1.7% | 0 | 0 |
| 6.4.0.4 | 1 | 7.5 | 1.7% | 0 | 0 |
| 6.4.0.3 | 1 | 7.5 | 1.7% | 0 | 0 |
| 6.4.0.2 | 1 | 7.5 | 1.7% | 0 | 0 |
| 6.4.0.1 | 1 | 7.5 | 1.7% | 0 | 0 |
| 6.4.0.0 | 5 | 6.6 | 1.0% | 0 | 0 |
| 6.4.0 | 6 | 7.0 | 1.4% | 0 | 0 |
| 6.3.1.9 | 1 | 7.5 | 1.7% | 0 | 0 |
| 6.3.1.8 | 1 | 7.5 | 1.7% | 0 | 0 |
| 6.3.1.7 | 1 | 7.5 | 1.7% | 0 | 0 |
| 6.3.1.6 | 2 | 5.5 | 1.3% | 0 | 0 |
| 6.3.1.5 | 2 | 5.5 | 1.3% | 0 | 0 |
| 6.3.1.4 | 2 | 5.5 | 1.3% | 0 | 0 |
| 6.3.1.3 | 2 | 5.5 | 1.3% | 0 | 0 |
| 6.3.1.2 | 2 | 5.5 | 1.3% | 0 | 0 |
| 6.3.1.17 | 1 | 7.5 | 1.7% | 0 | 0 |