Page 3 of 27 results (0.009 seconds)

CVSS: 8.6EPSS: 0%CPEs: 7EXPL: 0

IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621. IBM Security Identity Manager Adapters 6.0 y 7.0 no realizan chequeos de autenticación para un recurso o funcionalidad críticos, permitiendo que los usuarios anónimos accedan a áreas protegidas. IBM X-Force ID: 128621. • http://www.ibm.com/support/docview.wss?uid=swg22007375 http://www.securityfocus.com/bid/101013 https://exchange.xforce.ibmcloud.com/vulnerabilities/128621 • CWE-306: Missing Authentication for Critical Function •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 0

IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136. IBM Security Privileged Identity Manager versión 2.0.2 y 2.1.0 almacena información confidencial en parámetros de URL. Esto puede provocar una divulgación de información si partes no autorizadas tienen acceso a las URL a través de los registros del servidor, los encabezados de las peticiones, o el historial del navegador. • http://www.ibm.com/support/docview.wss?uid=swg22003092 http://www.securityfocus.com/bid/98829 https://exchange.xforce.ibmcloud.com/vulnerabilities/116136 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171. IBM Security Privileged Identity Manager versiones 2.0.2 y 2.1.0 almacena las credenciales de usuario en un texto claro que puede ser leído por un usuario local. IBM X-Force ID: 116171 • http://www.ibm.com/support/docview.wss?uid=swg22003092 http://www.securityfocus.com/bid/98825 https://exchange.xforce.ibmcloud.com/vulnerabilities/116171 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.9EPSS: 0%CPEs: 2EXPL: 0

IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM Security Privileged Identity Manager Virtual Appliance podría permitir a un atacante remoto obtener información sensible, causada por el error para habilitar correctamente HTTP Strict Transport Security. Un atacante podría explotar esta vulnerabilidad para obtener información sensible utilizando técnicas man-in-the-middle. • http://www.ibm.com/support/docview.wss?uid=swg21996614 http://www.securityfocus.com/bid/95197 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM Security Privileged Identity Manager Virtual Appliance versión 2.0.2 utiliza una configuración de bloqueo de cuentas inadecuada que podría permitir a un atacante remoto para credenciasles de cuenta por fuerza bruta. • http://www.ibm.com/support/docview.wss?uid=swg21994065 http://www.securityfocus.com/bid/94308 • CWE-284: Improper Access Control •