Critical severity9.8NVD Advisory· Published Oct 15, 2020· Updated Jun 17, 2026
CVE-2020-4499
CVE-2020-4499
Description
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:ibm:security_access_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:security_access_manager:*:*:*:*:*:*:*:*range: >=9.0.7.0,<9.0.7.2
- (no CPE)range: 9.0.7
cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*range: >=10.0.0,<10.0.0.1
- (no CPE)range: 10.0.0
- (no CPE)range: 10.0.0
- Range: 9.0.7
Patches
Vulnerability mechanics
References
2- www.ibm.com/support/pages/node/6348046nvdPatchVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/182216nvdVDB EntryVendor Advisory
News mentions
0No linked articles in our index yet.