Ibm Security Access Manager vulnerabilities
56 known vulnerabilities affecting ibm/security_access_manager.
Total CVEs
56
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH15MEDIUM34LOW4
Vulnerabilities
Page 2 of 3
CVE-2019-4152MEDIUMCVSS 4.4≥ 9.0.1, ≤ 9.0.6v9.0.1+5 more2019-06-25
CVE-2019-4152 [MEDIUM] CWE-384 CVE-2019-4152: IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manne
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.
cvelistv5nvd
CVE-2019-4156MEDIUMCVSS 5.9≥ 9.0.1, ≤ 9.0.6v9.0.1+5 more2019-06-25
CVE-2019-4156 [MEDIUM] CWE-327 CVE-2019-4156: IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms t
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158572.
cvelistv5nvd
CVE-2019-4158MEDIUMCVSS 5.4≥ 9.0.1, ≤ 9.0.6v9.0.1+5 more2019-06-25
CVE-2019-4158 [MEDIUM] CWE-862 CVE-2019-4158: IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct whi
IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality to unintended actors. IBM X-Force ID: 158574.
cvelistv5nvd
CVE-2019-4153MEDIUMCVSS 6.8≥ 9.0.1, ≤ 9.0.6v9.0.1+5 more2019-06-25
CVE-2019-4153 [MEDIUM] CWE-601 CVE-2019-4153: IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing at
IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted.
cvelistv5nvd
CVE-2019-4150LOWCVSS 3.7≥ 9.0.1, ≤ 9.0.6v9.0.1+5 more2019-06-25
CVE-2019-4150 [LOW] CWE-295 CVE-2019-4150: IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certi
IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-Force ID: 158510.
cvelistv5nvd
CVE-2018-1970HIGHCVSS 7.1≥ 7.0.1, ≤ 7.0.1.102019-02-04
CVE-2018-1970 [HIGH] CWE-611 CVE-2018-1970: IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack wh
IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 153751.
nvd
CVE-2018-1887HIGHCVSS 7.8≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1887 [MEDIUM] CWE-798 CVE-2018-1887: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 152078.
nvd
CVE-2018-1814HIGHCVSS 7.5≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1814 [MEDIUM] CWE-326 CVE-2018-1814: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses weaker th
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 150018.
nvd
CVE-2018-1740MEDIUMCVSS 5.4≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1740 [MEDIUM] CWE-79 CVE-2018-1740: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148419.
nvd
CVE-2018-1815MEDIUMCVSS 6.1≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1815 [MEDIUM] CWE-79 CVE-2018-1815: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X
nvd
CVE-2018-1805MEDIUMCVSS 4.3≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1805 [MEDIUM] CWE-200 CVE-2018-1805: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an e
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 149704.
nvd
CVE-2018-1803MEDIUMCVSS 6.1≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1803 [MEDIUM] CWE-1021 CVE-2018-1803: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the vi
nvd
CVE-2018-1813MEDIUMCVSS 6.5≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1813 [MEDIUM] CVE-2018-1813: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplet
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 150017.
nvd
CVE-2018-1653MEDIUMCVSS 5.4≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1653 [MEDIUM] CWE-79 CVE-2018-1653: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144726.
nvd
CVE-2018-1886MEDIUMCVSS 5.3≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1886 [MEDIUM] CWE-200 CVE-2018-1886: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sens
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 152021.
nvd
CVE-2018-1804LOWCVSS 3.7≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1804 [LOW] CWE-384 CVE-2018-1804: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set t
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 149703.
nvd
CVE-2018-1850HIGHCVSS 7.5v9.0.3.1v9.0.4.0+1 more2018-10-22
CVE-2018-1850 [HIGH] CVE-2018-1850: IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administ
IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations when Advanced Access Control services are running. IBM X-Force ID: 150998.
nvd
CVE-2018-1722CRITICALCVSS 10.0v9.0.4.0v9.0.5.02018-08-24
CVE-2018-1722 [CRITICAL] CVE-2018-1722: IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Adv
IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are running. IBM X-Force ID: 147370.
nvd
CVE-2017-1474MEDIUMCVSS 5.3≥ 9.0.0, ≤ 9.0.3.1v9.0.0.1+19 more2018-06-06
CVE-2017-1474 [MEDIUM] CWE-200 CVE-2017-1474: IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 disclo
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606.
cvelistv5nvd
CVE-2017-1480MEDIUMCVSS 4.3≥ 9.0.0, ≤ 9.0.3.1v9.0.0.1+18 more2018-06-06
CVE-2017-1480 [MEDIUM] CWE-532 CVE-2017-1480: IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potent
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
cvelistv5nvd