Vulnerabilities > IBM > Security Identity Governance AND Intelligence > 5.2.2.1

DATE CVE VULNERABILITY TITLE RISK
2018-08-06 CVE-2017-1409 Information Exposure vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 discloses sensitive information to unauthorized users.
network
low complexity
ibm CWE-200
5.0
2018-08-06 CVE-2017-1396 Permission Issues vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
network
low complexity
ibm CWE-275
5.5
2018-08-06 CVE-2017-1368 Session Fixation vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not set the secure attribute on authorization tokens or session cookies.
network
ibm CWE-384
4.3
2018-08-06 CVE-2017-1366 Inadequate Encryption Strength vulnerability in IBM Security Identity Governance and Intelligence
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
5.0
2018-07-13 CVE-2017-1395 Information Exposure vulnerability in IBM Security Identity Governance and Intelligence 5.2.2.1
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
ibm CWE-200
4.3
2018-07-13 CVE-2017-1367 Information Exposure vulnerability in IBM Security Identity Governance and Intelligence 5.2.2.1
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in URL parameters.
network
low complexity
ibm CWE-200
5.0