Vulnerabilities > Oneidentity > Cloud Access Manager

DATE CVE VULNERABILITY TITLE RISK
2019-11-04 CVE-2019-13497 Cross-Site Request Forgery (CSRF) vulnerability in Oneidentity Cloud Access Manager
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.
4.3
2019-11-04 CVE-2019-13496 Improper Validation of Integrity Check Value vulnerability in Oneidentity Cloud Access Manager
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.
4.3
2019-07-29 CVE-2019-13498 Cleartext Transmission of Sensitive Information vulnerability in Oneidentity Cloud Access Manager 8.1.3
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks.
network
high complexity
oneidentity CWE-319
7.4