
CVE-2021-20574
https://notcve.org/view.php?id=CVE-2021-20574
28 Jun 2021 — IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IBM X-Force ID: 199252. IBM Security Identity Manager Adapters versiones 6.0 y 7.0, podrían permitir a un atacante remoto autenticado conducir una inyección LDAP. Al usar una petición especialmente diseñada, un atacante podría explotar esta vulnerabilidad y tomar el contro d... • https://exchange.xforce.ibmcloud.com/vulnerabilities/199252 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2021-20573
https://notcve.org/view.php?id=CVE-2021-20573
28 Jun 2021 — IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199249. IBM Security Identity Manager Adapters versiones 6.0 y 7.0, son vulnerables a un desbordamiento de búfer en la región heap de la memoria, causado por una comprobación inapropiada de límites. Un atacante autenticado remoto podría desbordar el búfer y causar el bloqueo del... • https://exchange.xforce.ibmcloud.com/vulnerabilities/199249 • CWE-787: Out-of-bounds Write •

CVE-2021-20572
https://notcve.org/view.php?id=CVE-2021-20572
28 Jun 2021 — IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow the and cause the server to crash. IBM X-Force ID: 199247. IBM Security Identity Manager Adapters versiones 6.0 y 7.0, son vulnerables a un desbordamiento de búfer en la región stack de la memoria, causado por una comprobación inapropiada de límites. Un atacante autenticado remoto podría desbordar el búfer y causar el bloqueo d... • https://exchange.xforce.ibmcloud.com/vulnerabilities/199247 • CWE-787: Out-of-bounds Write •

CVE-2021-20494
https://notcve.org/view.php?id=CVE-2021-20494
28 Jun 2021 — IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bounds. An authenticared user could overflow the buffer and cause the service to crash. IBM X-Force ID: 197882. IBM Security Identity Manager Adapters versiones 6.0 y 7.0, son vulnerables a un desbordamiento de búfer en la región heap de la memoria, causado por una comprobación inapropiada de límites. Un usuario autenticado podría desbordar el búfer y causar el bloqueo del servicio. • https://exchange.xforce.ibmcloud.com/vulnerabilities/197882 • CWE-787: Out-of-bounds Write •

CVE-2021-29688
https://notcve.org/view.php?id=CVE-2021-29688
20 May 2021 — IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102. IBM Security Identity Manager versión 7.0.2, podría permitir a un atacante remoto obtener información confidencial cuando es devuelto un mensaje de error técnico detallado en el navegador. Esta información podría ser usada en nuevos ataques contra... • https://exchange.xforce.ibmcloud.com/vulnerabilities/200102 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVE-2019-4038
https://notcve.org/view.php?id=CVE-2019-4038
04 Feb 2019 — IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162. IBM Security Identity Manager 6.0 y 7.0 podría permitir que un atacante cree rutas de flujo de control mediante la aplicación, pudiendo omitir las comprobaciones de seguridad. La explotación de esta vulnerabilidad puede resultar en una form... • https://exchange.xforce.ibmcloud.com/vulnerabilities/156162 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2017-1405
https://notcve.org/view.php?id=CVE-2017-1405
08 Jun 2018 — IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 127392. IBM Security Identity Manager Virtual Appliance 7.0 procesa parches, backups de imágenes y otras actualizaciones sin verificar lo suficiente el origen e integridad del código. IBM X-Force ID: 127392. • http://www.ibm.com/support/docview.wss?uid=swg22013617 • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2018-1453
https://notcve.org/view.php?id=CVE-2018-1453
08 Jun 2018 — IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be automatically processed within the environment. IBM X-Force ID: 140055. IBM Security Identity Manager Virtual Appliance 7.0 permite que un atacante autenticado suba o transfiera archivos de tipos peligrosos que pueden procesarse automáticamente en el entorno. IBM X-Force ID: 140055. • http://www.ibm.com/support/docview.wss?uid=swg22013617 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2016-0351
https://notcve.org/view.php?id=CVE-2016-0351
21 Feb 2018 — IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890. IBM Security Identity Manager Virtual Appliance, en versiones 7.0.x anteriores a 7.0.1.3-ISS-SIM-IF0001 no establece la marca secure para la cookie de sesión en una sesión HTTPS. Esto facilita que atacantes r... • http://www-01.ibm.com/support/docview.wss?uid=swg21989198 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-0367
https://notcve.org/view.php?id=CVE-2016-0367
21 Feb 2018 — IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072. IBM Security Identity Manager Virtual Appliance, en versiones 7.0.x anteriores a la 7.0.1.3-ISS-SIM-IF0001 permite que usuarios autenticados remotos obtengan información sensible mediante la lectura de un mensaje de error. IBM X-Force ID: 112072. • http://www-01.ibm.com/support/docview.wss?uid=swg21989198 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •