Man-in-the-Middle Vulnerability in IBM Security Access Manager
CVE-2019-4150

3.7LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
25 June 2019

What is CVE-2019-4150?

IBM Security Access Manager versions 9.0.1 through 9.0.6 lack proper validation for certificates, allowing attackers to potentially spoof trusted entities through man-in-the-middle (MITM) attacks. This vulnerability can lead to unauthorized access and exposure of sensitive information, making it crucial for users to apply necessary patches and monitor their systems for suspicious activities.

Affected Version(s)

Security Access Manager 9.0.1

Security Access Manager 9.0.3

Security Access Manager 9.0.4

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.