CVE-2020-4499Missing Authorization in IBM Security Access Manager

Severity
9.8CRITICALNVD
EPSS
0.4%
top 40.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 15
Latest updateMay 24

Description

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDibm/security_verify_access10.0.010.0.0.1
NVDibm/security_access_manager9.0.7.09.0.7.2
CVEListV5ibm/security_verify_access10.0.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jhc9-5xjw-qfg8: IBM Security Access Manager 92022-05-24
CVEList
CVE-2020-4499: IBM Security Access Manager 92020-10-15

💬Community

1
Bugzilla
CVE-2019-7636 SDL: heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c2019-02-14
CVE-2020-4499 — Missing Authorization in IBM | cvebase