VYPR

Security Access Manager For Web 8.0 Firmware

by IBM

CVEs (99)

  • CVE-2016-3017HigFeb 1, 2017
    risk 0.49cvss 7.5epss 0.02

    IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations.

  • CVE-2015-5012HigFeb 15, 2016
    risk 0.49cvss 7.5epss 0.02

    The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection…

  • CVE-2015-5010HigFeb 15, 2016
    risk 0.49cvss 7.5epss 0.02

    IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

  • CVE-2019-4707HigJan 28, 2020
    risk 0.46cvss 7.1epss 0.01

    IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.

  • CVE-2019-4145HigJun 25, 2019
    risk 0.46cvss 7.1epss 0.00

    IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user which could be used in further attacks against the system. IBM X-Force ID: 158400.

  • CVE-2018-1970HigFeb 4, 2019
    risk 0.46cvss 7.1epss 0.02

    IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 153751.

  • CVE-2019-4153MedJun 25, 2019
    risk 0.44cvss 6.8epss 0.01

    IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed…

  • CVE-2020-4461MedMay 20, 2020
    risk 0.42cvss 6.5epss 0.01

    IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token claims manipulation without verification. IBM X-Force ID: 181481.

  • CVE-2016-3019MedJun 7, 2017
    risk 0.42cvss 6.5epss 0.01

    IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.

  • CVE-2016-3027MedFeb 1, 2017
    risk 0.42cvss 6.5epss 0.01

    IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory…

  • CVE-2016-3022MedFeb 1, 2017
    risk 0.42cvss 6.5epss 0.02

    IBM Security Access Manager for Web could allow an authenticated user to gain access to highly sensitive information due to incorrect file permissions.

  • CVE-2024-35139MedJun 28, 2024
    risk 0.40cvss 6.2epss 0.00

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.

  • CVE-2024-35137MedJun 28, 2024
    risk 0.40cvss 6.2epss 0.00

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.

  • CVE-2019-4552MedOct 15, 2020
    risk 0.40cvss 6.1epss 0.01

    IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This…

  • CVE-2019-4725MedOct 6, 2020
    risk 0.40cvss 6.1epss 0.01

    IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM…

  • CVE-2019-4157MedJun 25, 2019
    risk 0.40cvss 6.1epss 0.01

    IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…

  • CVE-2018-1815MedDec 13, 2018
    risk 0.40cvss 6.1epss 0.01

    IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality…

  • CVE-2018-1803MedDec 13, 2018
    risk 0.40cvss 6.1epss 0.01

    IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the…

  • CVE-2017-1534MedJan 10, 2018
    risk 0.40cvss 6.1epss 0.01

    IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL…

  • CVE-2017-1533MedJan 10, 2018
    risk 0.40cvss 6.1epss 0.01

    IBM Security Access Manager Appliance 9.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.…

Page 2 of 5