Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Security Identity Manager
Total 43 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-6111 1 Ibm 2 Security Identity Manager, Tivoli Identity Manager 2024-11-21 2.1 LOW 7.8 HIGH
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 store encrypted user credentials and the keystore password in cleartext in configuration files, which allows local users to decrypt SIM credentials via unspecified vectors. IBM X-Force ID: 96180.
CVE-2014-6109 1 Ibm 2 Security Identity Manager, Tivoli Identity Manager 2024-11-21 3.5 LOW 5.3 MEDIUM
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via vectors related to server side LDAP queries. IBM X-Force ID: 96173.
CVE-2014-6108 1 Ibm 2 Security Identity Manager, Tivoli Identity Manager 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 might allow man-in-the-middle attackers to obtain sensitive information by leveraging an unencrypted connection for interfaces. IBM X-Force ID: 96172.