Vulnerabilities > IBM > Security Identity Manager > 7.0.1.3

DATE CVE VULNERABILITY TITLE RISK
2019-02-04 CVE-2019-4038 Code Injection vulnerability in IBM Security Identity Manager
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks.
low complexity
ibm CWE-94
6.2
2019-02-04 CVE-2018-1962 Session Fixation vulnerability in IBM Security Identity Manager
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed.
local
low complexity
ibm CWE-384
2.1
2019-01-24 CVE-2018-1959 Use of Hard-coded Credentials vulnerability in IBM Security Identity Manager
IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
local
low complexity
ibm CWE-798
4.6
2017-02-01 CVE-2016-9739 Credentials Management vulnerability in IBM Security Identity Manager
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-255
2.1