cbcvebase.

Ibm Security Access Manager vulnerabilities

56 known vulnerabilities affecting ibm/security_access_manager.

Total CVEs
56
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH15MEDIUM34LOW4

Vulnerabilities

Page 3 of 3
CVE-2018-1653P4MEDIUMCVSS 5.4≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1653 [MEDIUM] CWE-79 CVE-2018-1653: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 144726.
nvd
CVE-2018-1740P4MEDIUMCVSS 5.4≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1740 [MEDIUM] CWE-79 CVE-2018-1740: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148419.
nvd
CVE-2023-38368P4MEDIUMCVSS 5.5≥ 10.0.0.0, ≤ 10.0.7.12024-06-27
CVE-2023-38368 [MEDIUM] CWE-863 CVE-2023-38368: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls. IBM X-Force ID: 261195.
nvd
CVE-2024-35139P4MEDIUMCVSS 5.5≥ 10.0.0.0, ≤ 10.0.7.12024-06-28
CVE-2024-35139 [MEDIUM] CWE-276 CVE-2024-35139: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sens IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.
nvd
CVE-2020-4661P4MEDIUMCVSS 5.3v9.0.7.0v9.0.72020-10-12
CVE-2020-4661 [MEDIUM] CWE-203 CVE-2020-4661: IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to o IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186142.
nvd
CVE-2020-4699P4MEDIUMCVSS 5.3v9.0.7.0v9.0.72020-10-12
CVE-2020-4699 [MEDIUM] CWE-203 CVE-2020-4699: IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to o IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186947.
nvd
CVE-2020-4660P4MEDIUMCVSS 5.3v9.0.7.0v9.0.72020-10-12
CVE-2020-4660 [MEDIUM] CWE-203 CVE-2020-4660: IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to o IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the system. IBM X-Force ID: 186140.
nvd
CVE-2017-1480P4MEDIUMCVSS 4.3≥ 9.0.0, ≤ 9.0.3.1v9.0.0.1+18 more2018-06-06
CVE-2017-1480 [MEDIUM] CWE-532 CVE-2017-1480: IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potent IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
nvd
CVE-2016-3051P4MEDIUMCVSS 4.3v9.0.0.1v9.0.0+2 more2017-06-07
CVE-2016-3051 [MEDIUM] CWE-264 CVE-2016-3051: IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privilege IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.
nvd
CVE-2017-1459P4MEDIUMCVSS 4.2v9.0.0.1v8.0.0+17 more2018-01-10
CVE-2017-1459 [MEDIUM] CWE-732 CVE-2017-1459: IBM Security Access Manager Appliance 8.0.0 and 9.0.0 specifies permissions for a security-critical IBM Security Access Manager Appliance 8.0.0 and 9.0.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 128378.
nvd
CVE-2018-1805P4MEDIUMCVSS 4.3≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1805 [MEDIUM] CWE-200 CVE-2018-1805: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an e IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 149704.
nvd
CVE-2019-4152P4MEDIUMCVSS 4.4≥ 9.0.1, ≤ 9.0.6v9.0.1+5 more2019-06-25
CVE-2019-4152 [MEDIUM] CWE-384 CVE-2019-4152: IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manne IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 158515.
nvd
CVE-2019-4150P4LOWCVSS 3.7≥ 9.0.1, ≤ 9.0.6v9.0.1+5 more2019-06-25
CVE-2019-4150 [LOW] CWE-295 CVE-2019-4150: IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certi IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-Force ID: 158510.
nvd
CVE-2018-1804P4LOWCVSS 3.7≥ 9.0.1.0, ≤ 9.0.5.02018-12-13
CVE-2018-1804 [LOW] CWE-384 CVE-2018-1804: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set t IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 149703.
nvd
CVE-2016-3045P4LOWCVSS 3.7v9.0.0v9.0.0.1+1 more2017-02-01
CVE-2016-3045 [LOW] CWE-200 CVE-2016-3045: IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history.
nvd
CVE-2017-1478P4LOWCVSS 3.3v9.0.0.1v9.0.0+5 more2018-01-11
CVE-2017-1478 [LOW] CWE-200 CVE-2017-1478: IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613.
nvd
Ibm Security Access Manager vulnerabilities | cvebase