CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

ibm

security_access_manager

43 known vulnerabilities · sorted by CVSS score

CVE-2018-1722
CRITICAL10.0

IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are running. IBM X-Force ID: 147370.

ibm / security_access_manager+1
Network
Published Aug 24, 2018
Page 1 of 3
CVE-2020-4499
CRITICAL9.8

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216.

ibm / security_access_manager+1
Network
Published Oct 15, 2020
CVE-2018-1850
HIGH8.8

IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations when Advanced Access Control services are running. IBM X-Force ID: 150998.

ibm / security_access_manager+2
Network
Published Oct 22, 2018
CVE-2019-4135
HIGH8.8

IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated users to impersonate other users. IBM X-Force ID: 158331.

ibm / security_access_manager
Network
Published Jun 25, 2019
CVE-2023-30998
HIGH7.8

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254649.

ibm / security_access_manager
Local
Published Jun 27, 2024
CVE-2023-30997
HIGH7.8

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254638.

ibm / security_access_manager
Local
Published Jun 27, 2024
CVE-2021-20439
HIGH7.5

IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.

ibm / security_access_manager+1
Network
Published Jul 15, 2021
CVE-2023-38370
HIGH7.5

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.

ibm / security_access_manager
Adjacent
Published Jun 27, 2024
CVE-2019-4036
HIGH7.5

IBM Security Access Manager Appliance could allow unauthenticated attacker to cause a denial of service in the reverse proxy component. IBM X-Force ID: 156159.

ibm / security_access_manager
Network
Published Oct 25, 2019
CVE-2019-4145
HIGH7.1

IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user which could be used in further attacks against the system. IBM X-Force ID: 158400.

ibm / security_access_manager
Local
Published Jun 25, 2019
CVE-2018-1970
HIGH7.1

IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 153751.

ibm / security_access_manager
Network
Published Feb 4, 2019
CVE-2019-4707
HIGH7.1

IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.

ibm / security_access_manager
Network
Published Jan 28, 2020
CVE-2019-4153
MEDIUM6.8

IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 158517.

ibm / security_access_manager
Network
Published Jun 25, 2019
CVE-2020-4461
MEDIUM6.5

IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing id_token claims manipulation without verification. IBM X-Force ID: 181481.

ibm / security_access_manager
Network
Published May 20, 2020
CVE-2024-35137
MEDIUM6.2

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.

ibm / security_access_manager
Local
Published Jun 28, 2024
CVE-2024-35139
MEDIUM6.2

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.

ibm / security_access_manager
Local
Published Jun 28, 2024
CVE-2019-4552
MEDIUM6.1

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 165960.

ibm / security_access_manager+1
Network
Published Oct 15, 2020
CVE-2019-4725
MEDIUM6.1

IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172131.

ibm / security_access_manager
Network
Published Oct 6, 2020
CVE-2019-4157
MEDIUM6.1

IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158573.

ibm / security_access_manager
Network
Published Jun 25, 2019
CVE-2018-1815
MEDIUM6.1

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150019.

ibm / security_access_manager
Network
Published Dec 13, 2018