Ibm Security Identity Manager vulnerabilities
45 known vulnerabilities affecting ibm/security_identity_manager.
Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH16MEDIUM25LOW2
Vulnerabilities
Page 3 of 3
CVE-2014-6168P4MEDIUMCVSS 6.0v5.1.0v5.1.0.3+12 more2014-12-29
CVE-2014-6168 [MEDIUM] CWE-352 CVE-2014-6168: Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15 IF0056 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd
CVE-2014-6096P4MEDIUMCVSS 4.3v6.0.0.0v6.0.0.1+2 more2014-11-18
CVE-2014-6096 [MEDIUM] CWE-79 CVE-2014-6096: Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 al
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2014-6107P4MEDIUMCVSS 4.3v6.0.0.0v6.0.0.1+2 more2014-11-18
CVE-2014-6107 [MEDIUM] CWE-200 CVE-2014-6107: IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to obtain sensitive co
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.
nvd
CVE-2014-6110P4LOWCVSS 2.1v6.0.0.0v6.0.0.1+2 more2014-11-18
CVE-2014-6110 [LOW] CWE-284 CVE-2014-6110: IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, whic
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation.
nvd
CVE-2018-1962P4LOWCVSS 3.3≥ 7.0.1, ≤ 7.0.1.10v7.0.12019-02-04
CVE-2018-1962 [LOW] CWE-384 CVE-2018-1962: IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the lo
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed. The lack of proper session termination may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 153658.
nvd
← Previous3 / 3