Security Identity Manager Virtual Appliance
security_identity_manager_virtual_appliance
Vendor: Ibm • 12 CVEs
CVEs (12)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Security Identity Manager Virtual Appliance Jun 17, 2026 Jul 1, 2020 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. IBM X-Force ID: 172...Show more |
1Ibm 1Security Identity Manager Virtual Appliance Jun 17, 2026 Jul 1, 2020 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 IBM Security Identity Manager Virtual Appliance 7.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 172015. |
1Ibm 1Security Identity Manager Virtual Appliance Jun 17, 2026 Jul 1, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by...Show more |
1Ibm 1Security Identity Manager Virtual Appliance Jun 17, 2026 Jul 1, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171512. |
1Ibm 1Security Identity Manager Virtual Appliance Nov 21, 2024 Jul 11, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153749. |
1Ibm 1Security Identity Manager Virtual Appliance Nov 21, 2024 Feb 21, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072. |
1Ibm 1Security Identity Manager Virtual Appliance Nov 21, 2024 Feb 21, 2018 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cook...Show more |
1Ibm 1Security Identity Manager Virtual Appliance Nov 21, 2024 Jan 12, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a...Show more |
1Ibm 1Security Identity Manager Virtual Appliance Nov 21, 2024 Jan 12, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator privileges via unspecified vectors. IBM X-Force ID: 111643. |
1Ibm 1Security Identity Manager Virtual Appliance Nov 21, 2024 Jan 12, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execute arbitrary code with administrator privileges via unspecified vectors...Show more |
1Ibm 1Security Identity Manager Virtual Appliance May 13, 2026 Feb 1, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more |
1Ibm 1Security Identity Manager Virtual Appliance May 13, 2026 Feb 1, 2017 N/A· v4 2.4 LOW· v3 2.1 LOW· v2 IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information. |