VendorsIBMsecurity_identity_managerall versions
Vulnerabilities

IBM Security Identity Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2014-6096
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2014-11-18 · Modified
4.3EPSS 0.023
CVE-2018-1962
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed. The lack of proper session termination may allow attackers with local access to login into a closed browser session. IBM X-Force ID: 153658.
Published 2019-02-04 · Modified
4.0EPSS 0.004
CVE-2014-6110
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation.
Published 2014-11-18 · Modified
2.1EPSS 0.006
← Prev2 / 2