Vulnerabilities > IBM > Security Access Manager > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-06-25 CVE-2019-4158 Missing Authorization vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality to unintended actors.
network
low complexity
ibm CWE-862
5.4
2019-06-25 CVE-2019-4157 Cross-site Scripting vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2019-06-25 CVE-2019-4156 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
high complexity
ibm CWE-327
5.9
2019-06-25 CVE-2019-4153 Open Redirect vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.8
2019-06-25 CVE-2019-4152 Session Fixation vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner.
local
low complexity
ibm CWE-384
4.4
2019-06-25 CVE-2019-4151 Inadequate Encryption Strength vulnerability in IBM Security Access Manager
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
high complexity
ibm CWE-326
5.9
2018-12-13 CVE-2018-1886 Information Exposure vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users.
network
low complexity
ibm CWE-200
5.3
2018-12-13 CVE-2018-1815 Cross-site Scripting vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2018-12-13 CVE-2018-1813 Unspecified vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity.
network
low complexity
ibm
6.5
2018-12-13 CVE-2018-1805 Information Exposure vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an error message that includes sensitive information about its environment, users, or associated data.
network
low complexity
ibm CWE-200
4.3