Vulnerabilities > IBM > Security Access Manager > 9.0.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-10-06 | CVE-2019-4725 | Cross-site Scripting vulnerability in IBM Security Access Manager IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. | 6.1 |
2020-05-20 | CVE-2020-4461 | Unspecified vulnerability in IBM Security Access Manager IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token claims manipulation without verification. | 6.5 |
2019-06-25 | CVE-2019-4158 | Missing Authorization vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality to unintended actors. | 5.4 |
2019-06-25 | CVE-2019-4157 | Cross-site Scripting vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. | 6.1 |
2019-06-25 | CVE-2019-4156 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 5.9 |
2019-06-25 | CVE-2019-4153 | Open Redirect vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. | 6.8 |
2019-06-25 | CVE-2019-4152 | Session Fixation vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. | 4.4 |
2019-06-25 | CVE-2019-4151 | Inadequate Encryption Strength vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 5.9 |
2019-06-25 | CVE-2019-4150 | Improper Certificate Validation vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. | 3.7 |
2019-06-25 | CVE-2019-4145 | Unspecified vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user which could be used in further attacks against the system. | 7.1 |