IBM / Security Access Manager 9.0 Firmware
25 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2017-1478 | IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613. | LOW | 3.3 | Jan 11, 2018 |
| CVE-2017-1533 | IBM Security Access Manager Appliance 9.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We… | MEDIUM | 6.1 | Jan 10, 2018 |
| CVE-2017-1459 | IBM Security Access Manager Appliance 8.0.0 and 9.0.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or m… | MEDIUM | 4.2 | Jan 10, 2018 |
| CVE-2017-1477 | IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exp… | HIGH | 8.1 | Nov 13, 2017 |
| CVE-2017-1453 | IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-cra… | HIGH | 8.8 | Nov 13, 2017 |
| CVE-2016-3051 | IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714. | MEDIUM | 4.3 | Jun 7, 2017 |
| CVE-2016-3019 | IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informati… | MEDIUM | 6.5 | Jun 7, 2017 |
| CVE-2016-5919 | IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly s… | HIGH | 7.5 | Feb 16, 2017 |
| CVE-2015-5013 | The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access. | MEDIUM | 5.5 | Feb 8, 2017 |
| CVE-2016-3020 | IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content validatio… | MEDIUM | 5.5 | Feb 7, 2017 |
| CVE-2016-3046 | IBM Security Access Manager for Web is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements which could allow the attacke… | LOW | 2.7 | Feb 1, 2017 |
| CVE-2016-3043 | IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transpo… | MEDIUM | 5.9 | Feb 1, 2017 |
| CVE-2016-3029 | IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tra… | HIGH | 8.8 | Feb 1, 2017 |
| CVE-2016-3027 | IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A re… | MEDIUM | 6.5 | Feb 1, 2017 |
| CVE-2016-3024 | IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system. | MEDIUM | 4.0 | Feb 1, 2017 |
| CVE-2016-3023 | IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names. | MEDIUM | 5.3 | Feb 1, 2017 |
| CVE-2016-3022 | IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permissions. | MEDIUM | 6.5 | Feb 1, 2017 |
| CVE-2016-3021 | IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP req… | LOW | 2.7 | Feb 1, 2017 |
| CVE-2016-3017 | IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations. | HIGH | 7.5 | Feb 1, 2017 |
| CVE-2016-3016 | IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, whi… | MEDIUM | 4.4 | Feb 1, 2017 |
| CVE-2016-2908 | IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML d… | CRITICAL | 9.1 | Feb 1, 2017 |
| CVE-2015-8531 | Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Web 8.0 before 8.0.1.3 IF4 and 9.0 before 9.0.0.1 IF1 allows remote attackers to in… | MEDIUM | 6.1 | Feb 15, 2016 |
| CVE-2015-5012 | The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not pro… | HIGH | 7.5 | Feb 15, 2016 |
| CVE-2015-5010 | IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not have a lockout mechanism for invalid log… | HIGH | 7.5 | Feb 15, 2016 |
| CVE-2015-5018 | IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote authenticat… | HIGH | 8.0 | Jan 2, 2016 |
Showing 1 to 25 of 25 CVEs