Ibm Corporation Identity Manager vulnerabilities
3 known vulnerabilities affecting ibm_corporation/identity_manager.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2016-9739HIGHCVSS 7.8v6.0v5.0+4 more2017-02-01
CVE-2016-9739 [HIGH] CWE-255 CVE-2016-9739: IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.
cvelistv5nvd
CVE-2016-9704MEDIUMCVSS 6.1v6.0v5.0+4 more2017-02-01
CVE-2016-9704 [MEDIUM] CWE-79 CVE-2016-9704: IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerab
IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2016-9703LOWCVSS 2.4v6.0v5.0+4 more2017-02-01
CVE-2016-9703 [LOW] CWE-384 CVE-2016-9703: IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
cvelistv5nvd