Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2016-0351
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890.
0
Attacker Value
Unknown
CVE-2016-0367
Disclosure Date: February 21, 2018 (last updated November 26, 2024)
IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072.
0
Attacker Value
Unknown
CVE-2016-9739
Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.
0
Attacker Value
Unknown
CVE-2016-9703
Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2016-9704
Disclosure Date: February 01, 2017 (last updated November 25, 2024)
IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
0
Attacker Value
Unknown
CVE-2016-0330
Disclosure Date: July 15, 2016 (last updated November 25, 2024)
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes it easier for remote attackers to obtain access by leveraging an attack against the password algorithm.
0
Attacker Value
Unknown
CVE-2016-0340
Disclosure Date: July 15, 2016 (last updated November 25, 2024)
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allows remote attackers to hijack sessions by leveraging an unattended workstation.
0
Attacker Value
Unknown
CVE-2016-0357
Disclosure Date: July 15, 2016 (last updated November 25, 2024)
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote attackers to conduct clickjacking attacks via a crafted web site.
0
Attacker Value
Unknown
CVE-2016-0338
Disclosure Date: July 15, 2016 (last updated November 25, 2024)
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext passwords by (1) reading a configuration file or (2) examining a process.
0
Attacker Value
Unknown
CVE-2016-0339
Disclosure Date: July 15, 2016 (last updated November 25, 2024)
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of "traffic records."
0