Vulnerabilities > IBM > Security Access Manager

DATE CVE VULNERABILITY TITLE RISK
2019-06-25 CVE-2019-4153 Open Redirect vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.8
2019-06-25 CVE-2019-4152 Session Fixation vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner.
local
low complexity
ibm CWE-384
4.4
2019-06-25 CVE-2019-4151 Inadequate Encryption Strength vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
high complexity
ibm CWE-326
5.9
2019-06-25 CVE-2019-4150 Improper Certificate Validation vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.
network
high complexity
ibm CWE-295
3.7
2019-06-25 CVE-2019-4145 Unspecified vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user which could be used in further attacks against the system.
local
low complexity
ibm
7.1
2019-06-25 CVE-2019-4135 Unspecified vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated users to impersonate other users.
network
low complexity
ibm
8.8
2019-02-04 CVE-2018-1970 XXE vulnerability in IBM Security Access Manager
IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2018-12-13 CVE-2018-1887 Use of Hard-coded Credentials vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
local
low complexity
ibm CWE-798
7.8
2018-12-13 CVE-2018-1886 Information Exposure vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users.
network
low complexity
ibm CWE-200
5.3
2018-12-13 CVE-2018-1815 Cross-site Scripting vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1