Information Disclosure in IBM Security Access Manager Appliance
CVE-2018-1805

4.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
13 December 2018

Summary

The IBM Security Access Manager Appliance versions 9.0.1.0 to 9.0.5.0 is susceptible to a vulnerability that generates error messages containing sensitive information about its internal environment, users, or associated data. This exposure could potentially be exploited by an attacker to gain insights into the system configuration and operational details, compromising user data and overall security. Proper security measures should be implemented to mitigate this risk and protect sensitive user data.

Affected Version(s)

Security Access Manager Appliance 9.0.1.0

Security Access Manager Appliance 9.0.2.0

Security Access Manager Appliance 9.0.3.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.