CVE-2019-4513
- EPSS 0.43%
- Veröffentlicht 26.08.2019 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:43:40
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume mem...
CVE-2017-1732
- EPSS 0.23%
- Veröffentlicht 17.08.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:22:17
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link ...
- EPSS 85.45%
- Veröffentlicht 28.01.2015 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 fu...
CVE-2013-5420
- EPSS 0.16%
- Veröffentlicht 23.12.2013 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request.
CVE-2013-5421
- EPSS 0.24%
- Veröffentlicht 22.12.2013 15:16:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote attackers to inject arbitrary web script or HTML via crafted input to an unspecified d...
CVE-2013-6745
- EPSS 0.18%
- Veröffentlicht 22.12.2013 15:16:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an uns...