Vulnerabilites related to IBM Corporation - Identity Manager
CVE-2016-9704 (GCVE-0-2016-9704)
Vulnerability from cvelistv5
Published
2017-02-01 22:00
Modified
2024-08-06 02:59
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Cross-Site Scripting
Summary
IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
IBM Corporation | Identity Manager |
Version: 6.0 Version: 5.0 Version: 5.1 Version: 6 Version: 7.0 Version: 7 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-06T02:59:03.286Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "1037765", "tags": [ "vdb-entry", "x_refsource_SECTRACK", "x_transferred" ], "url": "http://www.securitytracker.com/id/1037765" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg21996761" }, { "name": "95323", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/95323" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Identity Manager", "vendor": "IBM Corporation", "versions": [ { "status": "affected", "version": "6.0" }, { "status": "affected", "version": "5.0" }, { "status": "affected", "version": "5.1" }, { "status": "affected", "version": "6" }, { "status": "affected", "version": "7.0" }, { "status": "affected", "version": "7" } ] } ], "datePublic": "2017-01-04T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session." } ], "problemTypes": [ { "descriptions": [ { "description": "Cross-Site Scripting", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-07-24T12:57:01", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "name": "1037765", "tags": [ "vdb-entry", "x_refsource_SECTRACK" ], "url": "http://www.securitytracker.com/id/1037765" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg21996761" }, { "name": "95323", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/95323" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "ID": "CVE-2016-9704", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Identity Manager", "version": { "version_data": [ { "version_value": "6.0" }, { "version_value": "5.0" }, { "version_value": "5.1" }, { "version_value": "6" }, { "version_value": "7.0" }, { "version_value": "7" } ] } } ] }, "vendor_name": "IBM Corporation" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Cross-Site Scripting" } ] } ] }, "references": { "reference_data": [ { "name": "1037765", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id/1037765" }, { "name": "http://www.ibm.com/support/docview.wss?uid=swg21996761", "refsource": "CONFIRM", "url": "http://www.ibm.com/support/docview.wss?uid=swg21996761" }, { "name": "95323", "refsource": "BID", "url": "http://www.securityfocus.com/bid/95323" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2016-9704", "datePublished": "2017-02-01T22:00:00", "dateReserved": "2016-12-01T00:00:00", "dateUpdated": "2024-08-06T02:59:03.286Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2016-9739 (GCVE-0-2016-9739)
Vulnerability from cvelistv5
Published
2017-02-01 22:00
Modified
2024-08-06 02:59
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Obtain Information
Summary
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
IBM Corporation | Identity Manager |
Version: 6.0 Version: 5.0 Version: 5.1 Version: 6 Version: 7.0 Version: 7 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-06T02:59:03.353Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "1037765", "tags": [ "vdb-entry", "x_refsource_SECTRACK", "x_transferred" ], "url": "http://www.securitytracker.com/id/1037765" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg21996761" }, { "name": "95326", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/95326" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Identity Manager", "vendor": "IBM Corporation", "versions": [ { "status": "affected", "version": "6.0" }, { "status": "affected", "version": "5.0" }, { "status": "affected", "version": "5.1" }, { "status": "affected", "version": "6" }, { "status": "affected", "version": "7.0" }, { "status": "affected", "version": "7" } ] } ], "datePublic": "2017-01-04T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user." } ], "problemTypes": [ { "descriptions": [ { "description": "Obtain Information", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-07-24T12:57:01", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "name": "1037765", "tags": [ "vdb-entry", "x_refsource_SECTRACK" ], "url": "http://www.securitytracker.com/id/1037765" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg21996761" }, { "name": "95326", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/95326" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "ID": "CVE-2016-9739", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Identity Manager", "version": { "version_data": [ { "version_value": "6.0" }, { "version_value": "5.0" }, { "version_value": "5.1" }, { "version_value": "6" }, { "version_value": "7.0" }, { "version_value": "7" } ] } } ] }, "vendor_name": "IBM Corporation" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Obtain Information" } ] } ] }, "references": { "reference_data": [ { "name": "1037765", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id/1037765" }, { "name": "http://www.ibm.com/support/docview.wss?uid=swg21996761", "refsource": "CONFIRM", "url": "http://www.ibm.com/support/docview.wss?uid=swg21996761" }, { "name": "95326", "refsource": "BID", "url": "http://www.securityfocus.com/bid/95326" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2016-9739", "datePublished": "2017-02-01T22:00:00", "dateReserved": "2016-12-01T00:00:00", "dateUpdated": "2024-08-06T02:59:03.353Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2016-9703 (GCVE-0-2016-9703)
Vulnerability from cvelistv5
Published
2017-02-01 22:00
Modified
2024-08-06 02:59
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Obtain Information
Summary
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
References
► | URL | Tags | |||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
IBM Corporation | Identity Manager |
Version: 6.0 Version: 5.0 Version: 5.1 Version: 6 Version: 7.0 Version: 7 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-06T02:59:03.334Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "95327", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/95327" }, { "name": "1037765", "tags": [ "vdb-entry", "x_refsource_SECTRACK", "x_transferred" ], "url": "http://www.securitytracker.com/id/1037765" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg21996761" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Identity Manager", "vendor": "IBM Corporation", "versions": [ { "status": "affected", "version": "6.0" }, { "status": "affected", "version": "5.0" }, { "status": "affected", "version": "5.1" }, { "status": "affected", "version": "6" }, { "status": "affected", "version": "7.0" }, { "status": "affected", "version": "7" } ] } ], "datePublic": "2017-01-04T00:00:00", "descriptions": [ { "lang": "en", "value": "IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information." } ], "problemTypes": [ { "descriptions": [ { "description": "Obtain Information", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2017-07-24T12:57:01", "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm" }, "references": [ { "name": "95327", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/95327" }, { "name": "1037765", "tags": [ "vdb-entry", "x_refsource_SECTRACK" ], "url": "http://www.securitytracker.com/id/1037765" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://www.ibm.com/support/docview.wss?uid=swg21996761" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "psirt@us.ibm.com", "ID": "CVE-2016-9703", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Identity Manager", "version": { "version_data": [ { "version_value": "6.0" }, { "version_value": "5.0" }, { "version_value": "5.1" }, { "version_value": "6" }, { "version_value": "7.0" }, { "version_value": "7" } ] } } ] }, "vendor_name": "IBM Corporation" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "Obtain Information" } ] } ] }, "references": { "reference_data": [ { "name": "95327", "refsource": "BID", "url": "http://www.securityfocus.com/bid/95327" }, { "name": "1037765", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id/1037765" }, { "name": "http://www.ibm.com/support/docview.wss?uid=swg21996761", "refsource": "CONFIRM", "url": "http://www.ibm.com/support/docview.wss?uid=swg21996761" } ] } } } }, "cveMetadata": { "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "assignerShortName": "ibm", "cveId": "CVE-2016-9703", "datePublished": "2017-02-01T22:00:00", "dateReserved": "2016-12-01T00:00:00", "dateUpdated": "2024-08-06T02:59:03.334Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }