Show filters
614 Total Results
Displaying 371-380 of 614
Sort by:
Attacker Value
Unknown

NetIQ Identity Reporting XSS exposure

Disclosure Date: April 26, 2018 (last updated November 08, 2023)
NetIQ Identity Reporting, in versions prior to 5.5 Service Pack 1, is susceptible to an XSS attack.
0
Attacker Value
Unknown

IDM 4.6 Identity Applications information leakage

Disclosure Date: April 26, 2018 (last updated November 08, 2023)
IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.
0
Attacker Value
Unknown

CVE-2018-8716

Disclosure Date: April 25, 2018 (last updated November 26, 2024)
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
0
Attacker Value
Unknown

CVE-2014-6108

Disclosure Date: April 20, 2018 (last updated November 26, 2024)
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 might allow man-in-the-middle attackers to obtain sensitive information by leveraging an unencrypted connection for interfaces. IBM X-Force ID: 96172.
0
Attacker Value
Unknown

CVE-2014-6112

Disclosure Date: April 20, 2018 (last updated November 26, 2024)
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 make it easier for remote attackers to obtain sensitive information by leveraging support for weak SSL ciphers. IBM X-Force ID: 96184.
0
Attacker Value
Unknown

CVE-2014-6109

Disclosure Date: April 20, 2018 (last updated November 26, 2024)
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via vectors related to server side LDAP queries. IBM X-Force ID: 96173.
0
Attacker Value
Unknown

CVE-2014-6111

Disclosure Date: April 20, 2018 (last updated November 26, 2024)
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 store encrypted user credentials and the keystore password in cleartext in configuration files, which allows local users to decrypt SIM credentials via unspecified vectors. IBM X-Force ID: 96180.
0
Attacker Value
Unknown

CVE-2018-0275

Disclosure Date: April 19, 2018 (last updated November 26, 2024)
A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to access the device's shell. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by tricking the device into unlocking the support user account and accessing the tunnel password and device serial number. A successful exploit could allow the attacker to run any system command with root access. This affects Cisco Identity Services Engine (ISE) software versions prior to 2.2.0.470. Cisco Bug IDs: CSCvf54409.
0
Attacker Value
Unknown

CVE-2017-1705

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
IBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments. While this information is not visible at first it can be obtained by viewing the page source. IBM X-Force ID: 134427.
0
Attacker Value
Unknown

IDM Information Leakage

Disclosure Date: March 28, 2018 (last updated November 08, 2023)
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
0