Security Directory Server

Vendor:

First CVE: Jan 27, 2014 · Active for 12 years

22
Total CVEs
More Total CVEs than 94% of tracked products
3.1
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Directory Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 27, 2014
12 years ago
Most Recent CVE
Jul 25, 2024
729 days ago

CVE Severity & Scoring

Security Directory Server22 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (4.5%)
Network19 (86.4%)
Unknown2 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (86.4%)
High1 (4.5%)
Unknown2 (9.1%)
User Interaction
None16 (72.7%)
Unknown2 (9.1%)
Required4 (18.2%)
Privileges Required
Low3 (13.6%)
High1 (4.5%)
None16 (72.7%)
Unknown2 (9.1%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot"
Sep 8, 20239.128NONO
IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to e
Oct 14, 20239.127NONO
IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted We
Oct 2, 20198.226NONO
IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 165178.
Oct 2, 20197.525NONO
IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813.
Feb 4, 20207.523NONO
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain se
Jul 25, 20247.522NONO
IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:/
Oct 29, 20205.320NONO
IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attack
Feb 4, 20206.120NONO
IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 16595
Oct 2, 20195.320NONO
IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attac
Oct 14, 20235.919NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Security Directory Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.2.019.11.5%00
6.4.0.817.51.7%00
6.4.0.717.51.7%00
6.4.0.617.51.7%00
6.4.0.517.51.7%00
6.4.0.417.51.7%00
6.4.0.317.51.7%00
6.4.0.217.51.7%00
6.4.0.117.51.7%00
6.4.0.056.61.0%00
6.4.067.01.4%00
6.3.1.917.51.7%00
6.3.1.817.51.7%00
6.3.1.717.51.7%00
6.3.1.625.51.3%00
6.3.1.525.51.3%00
6.3.1.425.51.3%00
6.3.1.325.51.3%00
6.3.1.225.51.3%00
6.3.1.1717.51.7%00