Ibm Security Identity Manager vulnerabilities

45 known vulnerabilities affecting ibm/security_identity_manager.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH16MEDIUM25LOW2

Vulnerabilities

Page 3 of 3
CVE-2014-6095MEDIUMCVSS 5.0v6.0.0.0v6.0.0.1+2 more2014-11-18
CVE-2014-6095 [MEDIUM] CWE-22 CVE-2014-6095: Directory traversal vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows re Directory traversal vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to read arbitrary files via unspecified vectors.
nvd
CVE-2014-6105MEDIUMCVSS 4.3v6.0.0.0v6.0.0.1+2 more2014-11-18
CVE-2014-6105 [MEDIUM] CWE-20 CVE-2014-6105: IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjackin IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
nvd
CVE-2014-6098MEDIUMCVSS 5.0v6.0.0.0v6.0.0.1+2 more2014-11-18
CVE-2014-6098 [MEDIUM] CWE-255 CVE-2014-6098: IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext passwords via a crafted request.
nvd
CVE-2014-6110LOWCVSS 2.1v6.0.0.0v6.0.0.1+2 more2014-11-18
CVE-2014-6110 [LOW] CWE-284 CVE-2014-6110: IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, whic IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation.
nvd
CVE-2014-0961MEDIUMCVSS 6.0v6.0.0v6.0.0.12014-06-08
CVE-2014-0961 [MEDIUM] CWE-352 CVE-2014-0961: Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0 Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
nvd