IBM / Security Access Manager for Mobile 8.0 Firmware
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2016-3029 | IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tra… | HIGH | 8.8 | Feb 1, 2017 |
| CVE-2016-3027 | IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A re… | MEDIUM | 6.5 | Feb 1, 2017 |
| CVE-2016-3024 | IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system. | MEDIUM | 4.0 | Feb 1, 2017 |
| CVE-2016-3023 | IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names. | MEDIUM | 5.3 | Feb 1, 2017 |
| CVE-2016-3022 | IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permissions. | MEDIUM | 6.5 | Feb 1, 2017 |
| CVE-2016-3021 | IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP req… | LOW | 2.7 | Feb 1, 2017 |
| CVE-2016-3017 | IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations. | HIGH | 7.5 | Feb 1, 2017 |
| CVE-2016-3016 | IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, whi… | MEDIUM | 4.4 | Feb 1, 2017 |
| CVE-2016-2908 | IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML d… | CRITICAL | 9.1 | Feb 1, 2017 |
| CVE-2014-6079 | Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x befor… | MEDIUM | 4.3 | Oct 3, 2014 |
| CVE-2014-4823 | The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Mana… | HIGH | 10.0 | Oct 3, 2014 |
| CVE-2014-7169 KEV | bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271) | CRITICAL | 9.8 | Sep 25, 2014 |
| CVE-2014-6271 KEV | bash: specially-crafted environment variables can be used to inject shell commands | CRITICAL | 9.8 | Sep 24, 2014 |
Showing 1 to 13 of 13 CVEs