Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2021-20574
Disclosure Date: June 22, 2021 (last updated November 28, 2024)
IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IBM X-Force ID: 199252.
0
Attacker Value
Unknown
CVE-2021-20494
Disclosure Date: June 22, 2021 (last updated November 28, 2024)
IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bounds. An authenticared user could overflow the buffer and cause the service to crash. IBM X-Force ID: 197882.
0
Attacker Value
Unknown
CVE-2021-20573
Disclosure Date: June 22, 2021 (last updated November 28, 2024)
IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199249.
0
Attacker Value
Unknown
CVE-2021-20572
Disclosure Date: June 22, 2021 (last updated November 28, 2024)
IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199247.
0
Attacker Value
Unknown
CVE-2018-2019
Disclosure Date: January 18, 2019 (last updated November 27, 2024)
IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 155265.
0
Attacker Value
Unknown
CVE-2017-1483
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621.
0
Attacker Value
Unknown
CVE-2017-1407
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 127394.
0
Attacker Value
Unknown
CVE-2014-6106
Disclosure Date: September 18, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors.
0
Attacker Value
Unknown
CVE-2014-6105
Disclosure Date: November 18, 2014 (last updated October 05, 2023)
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-6096
Disclosure Date: November 18, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
0