Weak Cryptographic Algorithms in IBM Security Access Manager
CVE-2019-4151
5.9MEDIUM
Summary
IBM Security Access Manager versions 9.0.1 to 9.0.6 have been identified to use encryption algorithms that do not meet expected security standards. This vulnerability potentially allows attackers to decrypt sensitive information, presenting a significant risk to data integrity and confidentiality. Organizations using affected versions are urged to review their security measures and apply relevant patches or updates to mitigate risks associated with this cryptographic weakness.
Affected Version(s)
Security Access Manager 9.0.1
Security Access Manager 9.0.3
Security Access Manager 9.0.4
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved