Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
security identity manager vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2018-1956
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for malicious users to compromise user accounts. IBM X-Force ID: 153628.
Ibm Security Identity Manager
6.5
CVSSv2
CVE-2018-1969
IBM Security Identity Manager 6.0.0 allows the malicious user to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 153750.
Ibm Security Identity Manager
4.3
CVSSv2
CVE-2018-1967
IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force...
Ibm Security Identity Manager
4.6
CVSSv2
CVE-2018-1443
An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authen...
Ibm Security Access Manager
Ibm Tivoli Federated Identity Manager 6.2.0
Ibm Tivoli Federated Identity Manager 6.2.2
Ibm Tivoli Federated Identity Manager 6.2.1
7.5
CVSSv2
CVE-2019-4675
IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511.
Ibm Security Identity Manager 7.0.1
9.3
CVSSv2
CVE-2019-4561
IBM Security Identity Manager 6.0.0 could allow a remote malicious user to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute ...
Ibm Security Identity Manager 6.0.0
4
CVSSv2
CVE-2019-4674
IBM Security Identity Manager 7.0.1 could allow a remote malicious user to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 171510.
Ibm Security Identity Manager 7.0.1
1.9
CVSSv2
CVE-2014-8923
The (1) IBM Tivoli Identity Manager Active Directory adapter prior to 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter prior to 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administ...
Ibm Security Identity Manager Active Directory Adapter
Ibm Tivoli Identity Manager Active Directory Adapter
4.3
CVSSv2
CVE-2016-0366
IBM Security Identity Manager Virtual Appliance 7.0.x prior to 7.0.1.3-ISS-SIM-IF0001 might allow remote malicious users to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071.
Ibm Security Privileged Identity Manager 2.0
4
CVSSv2
CVE-2017-1705
IBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments. While this information is not visible at first it can be obtained by viewing the page source. IBM X-Force ID: 134427.
Ibm Security Privileged Identity Manager 2.1.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »