4.3
CVSSv2

CVE-2019-13496

Published: 04/11/2019 Updated: 05/11/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

One Identity Cloud Access Manager prior to 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oneidentity cloud access manager

oneidentity cloud access manager 8.1.4

Github Repositories

CVE-2019-13496 Exploit Title: OTP bypass (Filed Integrity check) Date: 07/10/2019 Exploit Author: Furqan Khan Vendor Homepage: wwwoneidentitycom/ Software Link: wwwoneidentitycom/products/cloud-access-manager/ Version: 813 Tested on: Kali Linux , Windows 7 ,Ubantu 1604 To exploit the OPT bypass vulnerability ,an attacker makes use of an earlier discovere