IBM / Security Access Manager
48 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-35139 | IBM Security Access Manager Docker information disclosure | MEDIUM | 6.2 | Jun 28, 2024 |
| CVE-2024-35137 | IBM Security Access Manager Docker information disclosure | MEDIUM | 6.2 | Jun 28, 2024 |
| CVE-2023-38370 | IBM Security Access Manager Docker information disclosure | HIGH | 7.5 | Jun 27, 2024 |
| CVE-2023-38368 | IBM Security Access Manager Docker information disclosure | MEDIUM | 5.5 | Jun 27, 2024 |
| CVE-2023-30997 | IBM Security Access Manager Docker privilege escalation | HIGH | 7.8 | Jun 27, 2024 |
| CVE-2023-30998 | IBM Security Access Manager Docker privilege escalation | HIGH | 7.8 | Jun 27, 2024 |
| CVE-2023-38371 | IBM Security Access Manager Docker information disclosure | HIGH | 7.5 | Jun 27, 2024 |
| CVE-2021-20439 | IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized u… | HIGH | 7.5 | Jul 15, 2021 |
| CVE-2020-4499 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentica… | CRITICAL | 9.8 | Oct 15, 2020 |
| CVE-2019-4552 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this… | MEDIUM | 6.1 | Oct 15, 2020 |
| CVE-2020-4699 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which cou… | MEDIUM | 5.3 | Oct 12, 2020 |
| CVE-2020-4661 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which cou… | MEDIUM | 5.3 | Oct 12, 2020 |
| CVE-2020-4660 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which cou… | MEDIUM | 5.3 | Oct 12, 2020 |
| CVE-2019-4725 | IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web… | MEDIUM | 6.1 | Oct 6, 2020 |
| CVE-2020-4461 | IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token claims manipulation without verificatio… | MEDIUM | 6.5 | May 20, 2020 |
| CVE-2019-4707 | IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could… | HIGH | 7.1 | Jan 28, 2020 |
| CVE-2019-4036 | IBM Security Access Manager Appliance could allow unauthenticated attacker to cause a denial of service in the reverse proxy component. IBM X-Force ID: 156159. | HIGH | 7.5 | Oct 25, 2019 |
| CVE-2019-4158 | IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality t… | MEDIUM | 5.4 | Jun 25, 2019 |
| CVE-2019-4157 | IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th… | MEDIUM | 6.1 | Jun 25, 2019 |
| CVE-2019-4156 | IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inf… | MEDIUM | 5.9 | Jun 25, 2019 |
| CVE-2019-4153 | IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victi… | MEDIUM | 6.8 | Jun 25, 2019 |
| CVE-2019-4152 | IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of proper session expiration may allow attacker… | MEDIUM | 4.4 | Jun 25, 2019 |
| CVE-2019-4151 | IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inf… | MEDIUM | 5.9 | Jun 25, 2019 |
| CVE-2019-4150 | IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could allow an attacker to spoof a trusted ent… | LOW | 3.7 | Jun 25, 2019 |
| CVE-2019-4145 | IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user which could be used in further attacks… | HIGH | 7.1 | Jun 25, 2019 |
Showing 1 to 25 of 48 CVEs