Ibm Security Access Manager vulnerabilities
56 known vulnerabilities affecting ibm/security_access_manager.
Total CVEs
56
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH15MEDIUM34LOW4
Vulnerabilities
Page 1 of 3
CVE-2018-1722P2CRITICALCVSS 10.0v9.0.4.0v9.0.5.02018-08-24
CVE-2018-1722 [CRITICAL] CVE-2018-1722: IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Adv
IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are running. IBM X-Force ID: 147370.
nvd
CVE-2017-1453P2HIGHCVSS 8.8v9.0.32017-11-13
CVE-2017-1453 [HIGH] CWE-78 CVE-2017-1453: IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute a
IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 128372.
nvd
CVE-2016-3028P3CRITICALCVSS 9.1v9.0.0v9.0.0.1+1 more2016-11-25
CVE-2016-3028 [CRITICAL] CWE-78 CVE-2016-3028: IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Ma
IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
nvd
CVE-2020-4499P3CRITICALCVSS 9.8≥ 9.0.7.0, < 9.0.7.2v9.0.72020-10-15
CVE-2020-4499 [CRITICAL] CVE-2020-4499: IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216.
nvd
CVE-2019-4135P3HIGHCVSS 8.8≥ 9.0.1, ≤ 9.0.6v9.0.1+5 more2019-06-25
CVE-2019-4135 [HIGH] CVE-2019-4135: IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could a
IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated users to impersonate other users. IBM X-Force ID: 158331.
nvd
CVE-2018-1850P3HIGHCVSS 7.5v9.0.3.1v9.0.4.0+1 more2018-10-22
CVE-2018-1850 [HIGH] CVE-2018-1850: IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administ
IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations when Advanced Access Control services are running. IBM X-Force ID: 150998.
nvd
CVE-2017-1477P3HIGHCVSS 8.1v9.0.32017-11-13
CVE-2017-1477 [HIGH] CWE-611 CVE-2017-1477: IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) a
IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128612.
nvd
CVE-2016-3025P3HIGHCVSS 8.1v9.0.0v9.0.0.1+1 more2016-11-25
CVE-2016-3025 [HIGH] CWE-254 CVE-2016-3025: IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before
IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
nvd
CVE-2018-1970P3HIGHCVSS 7.1≥ 7.0.1, ≤ 7.0.1.102019-02-04
CVE-2018-1970 [HIGH] CWE-611 CVE-2018-1970: IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack wh
IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 153751.
nvd
CVE-2023-38371P3HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.7.12024-06-27
CVE-2023-38371 [HIGH] CWE-327 CVE-2023-38371: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 261198.
nvd
CVE-2021-20439P3HIGHCVSS 7.5v9.02021-07-15
CVE-2021-20439 [HIGH] CWE-522 CVE-2021-20439: IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials
IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.
nvd
CVE-2023-30998P3HIGHCVSS 7.8≥ 10.0.0.0, ≤ 10.0.7.12024-06-27
CVE-2023-30998 [HIGH] CWE-250 CVE-2023-30998: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254649.
nvd
CVE-2023-30997P3HIGHCVSS 7.8≥ 10.0.0.0, ≤ 10.0.7.12024-06-27
CVE-2023-30997 [HIGH] CWE-250 CVE-2023-30997: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254638.
nvd
CVE-2019-4707P3HIGHCVSS 7.1v9.0.7.02020-01-28
CVE-2019-4707 [HIGH] CWE-611 CVE-2019-4707: IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.
nvd
CVE-2018-1814P3HIGHCVSS 7.5≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1814 [HIGH] CWE-326 CVE-2018-1814: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses weaker th
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 150018.
nvd
CVE-2018-1887P3HIGHCVSS 7.8≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1887 [HIGH] CWE-798 CVE-2018-1887: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 152078.
nvd
CVE-2017-1473P3HIGHCVSS 7.5v9.0.0.1v8.0.0+17 more2018-04-23
CVE-2017-1473 [HIGH] CWE-326 CVE-2017-1473: IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker th
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6 and 9.0.0 through 9.0.3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 128605.
nvd
CVE-2023-38370P3MEDIUMCVSS 6.5≥ 10.0.0.0, ≤ 10.0.7.12024-06-27
CVE-2023-38370 [MEDIUM] CWE-276 CVE-2023-38370: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could al
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.
nvd
CVE-2020-4461P4MEDIUMCVSS 6.5≥ 9.0, < 9.0.7.12020-05-20
CVE-2020-4461 [MEDIUM] CVE-2020-4461: IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security b
IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token claims manipulation without verification. IBM X-Force ID: 181481.
nvd
CVE-2018-1813P4MEDIUMCVSS 6.5≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1813 [MEDIUM] CVE-2018-1813: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplet
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 150017.
nvd
1 / 3Next →