CVE-2020-4461
https://notcve.org/view.php?id=CVE-2020-4461
IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token claims manipulation without verification. IBM X-Force ID: 181481. El IBM Security Access Manager Appliance versión 9.0.7.1, podría permitir a un usuario autentificado omitir la seguridad al permitir una manipulación de las peticiones de id_token sin verificación. IBM X-Force ID: 181481. • https://exchange.xforce.ibmcloud.com/vulnerabilities/181481 https://www.ibm.com/support/pages/node/6211847 •
CVE-2019-4707
https://notcve.org/view.php?id=CVE-2019-4707
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018. IBM Security Access Manager Appliance versión 9.0.7.0, es vulnerable a un ataque de tipo XML External Entity Injection (XXE) cuando se procesan datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información confidencial o consumir recursos de memoria. • https://exchange.xforce.ibmcloud.com/vulnerabilities/172018 https://www.ibm.com/support/pages/node/1284034 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2019-4036
https://notcve.org/view.php?id=CVE-2019-4036
IBM Security Access Manager Appliance could allow unauthenticated attacker to cause a denial of service in the reverse proxy component. IBM X-Force ID: 156159. IBM Security Access Manager Appliance, podría permitir a un atacante no autenticado causar una denegación de servicio en el componente proxy inverso. ID de IBM X-Force: 156159. • https://exchange.xforce.ibmcloud.com/vulnerabilities/156159 https://www.ibm.com/support/pages/node/1072704 •
CVE-2019-4513
https://notcve.org/view.php?id=CVE-2019-4513
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 164555. IBM Security Access Manager for Enterprise Single Sign-On versión 8.2.2, es vulnerable a un ataque de tipo XML External Entity (XXE) cuando se procesa datos XML. Un atacante remoto podría explotar esta vulnerabilidad para exponer información confidencial o consumir recursos de la memoria. • http://www.ibm.com/support/docview.wss?uid=ibm10996716 https://exchange.xforce.ibmcloud.com/vulnerabilities/164555 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2019-4158
https://notcve.org/view.php?id=CVE-2019-4158
IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality to unintended actors. IBM X-Force ID: 158574. IBM Security Access Manager versión 9.0.1 hasta 9.0.6, no prueba que la identidad de un usuario sea la correcta, lo que puede conllevar a la exposición de recursos o funcionalidades a actores no deseados. ID de IBM X-Force: 158574 • https://exchange.xforce.ibmcloud.com/vulnerabilities/158574 https://www.ibm.com/support/docview.wss?uid=ibm10888379 • CWE-862: Missing Authorization •