IBM Security Identity Manager 6.0.2

CPE Details

IBM Security Identity Manager 6.0.2
6.0.2
2021-05-24
15h18 +00:00
2021-06-04
17h17 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:ibm:security_identity_manager:6.0.2:*:*:*:*:*:*:*

Informations

Vendor

ibm

Product

security_identity_manager

Version

6.0.2

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2021-29864 2022-08-30 18h40 +00:00 IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 206089
6.1
Moyen
CVE-2021-20488 2021-06-16 16h15 +00:00 IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users in the Windows AD environment when IBM Security Identity Manager Windows Password Synch Plug-in is deployed and configured. IBM X-Force ID: 197789.
6.5
Moyen
CVE-2021-20483 2021-06-16 16h15 +00:00 IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197591.
6.5
Moyen
CVE-2021-29688 2021-05-20 15h10 +00:00 IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 200102.
7.5
Haute
CVE-2021-29687 2021-05-20 15h10 +00:00 IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 200018
5.3
Moyen