IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are running. IBM X-Force ID: 147370.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HIBM Security Access Manager
APPIbm9.0.4.09.0.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
References
Related vulnerabilities
CVE-2020-4499CRITICAL9.8PL ✓same product
IBM Security Access Manager / Verify Access — ominięcie uwierzytelnienia OAuth
CVE-2016-3028CRITICAL9.1PL ✓same product
Command Injection w IBM Security Access Manager — wykonanie dowolnych poleceń
CVE-2023-30997HIGH7.8same product
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access du...
CVE-2023-30998HIGH7.8same product
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access du...
CVE-2023-38370HIGH7.5same product
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user...