Home/Product/ibm security identity manager virtual appliance
Product

ibm security identity manager virtual appliance

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2019-4706
all versions
IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature and give
2.7LOW
CVE-2019-4705
all versions
IBM Security Identity Manager Virtual Appliance 7.0.2 discloses sensitive information to unauthorized users. The information can b
2.7LOW
CVE-2019-4704
all versions
IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or session cookies
4.3MEDIUM
CVE-2019-4676
all versions
IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local
7.8HIGH
CVE-2018-1968
>= 7.0.1 and <= 7.0.1.12
IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used to mount fu
5.3MEDIUM
CVE-2016-0367
all versions
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain se
4.3MEDIUM
CVE-2016-0351
all versions
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session c
3.7LOW
CVE-2016-0332
all versions
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restric
9.8CRITICAL
CVE-2016-0327
all versions
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to g
7.8HIGH
CVE-2016-0324
all versions
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authentic
8.8HIGH
CVE-2016-9704
all versions
IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed ar
6.1MEDIUM
CVE-2016-9703
all versions
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with phy
2.4LOW