5.8
CVSSv2

CVE-2019-13498

Published: 29/07/2019 Updated: 28/02/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 517
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oneidentity cloud access manager 8.1.3

Github Repositories

CVE-2019-13498

CVE-2019-13498 Exploit Title: MITM - Missing HSTS causing credential theft and content manipulation Date: 07/10/2019 Exploit Author: Furqan Khan Vendor Homepage: wwwoneidentitycom/ Software Link: wwwoneidentitycom/products/cloud-access-manager/ Version: 813 Tested on: Kali Linux , Windows 7 ,Ubantu 1604 To conduct the MITM attack and steal username , pass

CVE-2019-13496 Exploit Title: OTP bypass (Filed Integrity check) Date: 07/10/2019 Exploit Author: Furqan Khan Vendor Homepage: wwwoneidentitycom/ Software Link: wwwoneidentitycom/products/cloud-access-manager/ Version: 813 Tested on: Kali Linux , Windows 7 ,Ubantu 1604 To exploit the OPT bypass vulnerability ,an attacker makes use of an earlier discovere