Ibm Security Access Manager Docker vulnerabilities

5 known vulnerabilities affecting ibm/security_access_manager_docker.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-30998HIGHCVSS 7.8≥ 10.0.0.0, ≤ 10.0.7.12024-06-27
CVE-2023-30998 [HIGH] CWE-250 CVE-2023-30998: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254649.
cvelistv5nvd
CVE-2023-30997HIGHCVSS 7.8≥ 10.0.0.0, ≤ 10.0.7.12024-06-27
CVE-2023-30997 [HIGH] CWE-250 CVE-2023-30997: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254638.
cvelistv5nvd
CVE-2023-38371HIGHCVSS 7.5≥ 10.0.0.0, ≤ 10.0.7.12024-06-27
CVE-2023-38371 [MEDIUM] CWE-327 CVE-2023-38371: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 261198.
cvelistv5nvd
CVE-2023-38370MEDIUMCVSS 6.5≥ 10.0.0.0, ≤ 10.0.7.12024-06-27
CVE-2023-38370 [HIGH] CWE-276 CVE-2023-38370: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could al IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.
cvelistv5nvd
CVE-2023-38368MEDIUMCVSS 5.5≥ 10.0.0.0, ≤ 10.0.7.12024-06-27
CVE-2023-38368 [MEDIUM] CWE-863 CVE-2023-38368: IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls. IBM X-Force ID: 261195.
cvelistv5nvd