Security Access Manager For Enterprise Single Sign On
security_access_manager_for_enterprise_single_sign-on
Vendor: Ibm • 6 CVEs
CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Security Access Manager For Enterprise Single Sign On Nov 21, 2024 Aug 26, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensit...Show more |
1Ibm 1Security Access Manager For Enterprise Single Sign On Nov 21, 2024 Aug 17, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a...Show more |
7Apple DebianGnu+4 more18Communications Application Session Controller Communications Eagle Application ProcessorCommunications Eagle Lnp Application Processor+15 moreMay 6, 2026 Jan 28, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostb...Show more |
1Ibm 1Security Access Manager For Enterprise Single Sign On Apr 29, 2026 Dec 23, 2013 N/A· v4 N/A· v3 3.5 LOW· v2 The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request. |
1Ibm 1Security Access Manager For Enterprise Single Sign On Apr 29, 2026 Dec 22, 2013 N/A· v4 N/A· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to inject arbitrary web script or HT...Show more |
1Ibm 1Security Access Manager For Enterprise Single Sign On Apr 29, 2026 Dec 22, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote attackers to inject arbitrary web script or HTML via cra...Show more |