Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2017-1489
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.
0
Attacker Value
Unknown
CVE-2016-3045
Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history.
0
Attacker Value
Unknown
CVE-2015-4963
Disclosure Date: November 08, 2015 (last updated October 05, 2023)
IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors.
0