Vulnerabilities > IBM > Security Access Manager
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-06-25 | CVE-2019-4153 | Open Redirect vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. | 6.8 |
2019-06-25 | CVE-2019-4152 | Session Fixation vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. | 4.4 |
2019-06-25 | CVE-2019-4151 | Inadequate Encryption Strength vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 5.9 |
2019-06-25 | CVE-2019-4150 | Improper Certificate Validation vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. | 3.7 |
2019-06-25 | CVE-2019-4145 | Unspecified vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user which could be used in further attacks against the system. | 7.1 |
2019-06-25 | CVE-2019-4135 | Unspecified vulnerability in IBM Security Access Manager IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated users to impersonate other users. | 8.8 |
2019-02-04 | CVE-2018-1970 | XXE vulnerability in IBM Security Access Manager IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. | 7.1 |
2018-12-13 | CVE-2018-1887 | Use of Hard-coded Credentials vulnerability in IBM Security Access Manager IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | 7.8 |
2018-12-13 | CVE-2018-1886 | Information Exposure vulnerability in IBM Security Access Manager IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. | 5.3 |
2018-12-13 | CVE-2018-1815 | Cross-site Scripting vulnerability in IBM Security Access Manager IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scripting. | 6.1 |