Vulnerabilities > IBM > Security Identity Manager Adapter > High

DATE CVE VULNERABILITY TITLE RISK
2021-06-28 CVE-2021-20574 Injection vulnerability in IBM Security Identity Manager Adapter 6.0.0.0/7.0.0.0
IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection.
network
low complexity
ibm CWE-74
8.8
2016-07-15 CVE-2016-0340 Improper Access Control vulnerability in IBM Security Identity Manager Adapter
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allows remote attackers to hijack sessions by leveraging an unattended workstation.
local
high complexity
ibm CWE-284
7.4
2016-07-15 CVE-2016-0330 Credentials Management vulnerability in IBM Security Identity Manager Adapter
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes it easier for remote attackers to obtain access by leveraging an attack against the password algorithm.
network
low complexity
ibm CWE-255
7.3