Security Identity Manager

Vendor:

First CVE: Jun 8, 2014 · Active for 12 years

43
Total CVEs
More Total CVEs than 97% of tracked products
6.1
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Identity Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 8, 2014
12 years ago
Most Recent CVE
Aug 30, 2022
1,425 days ago

CVE Severity & Scoring

Security Identity Manager43 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local5 (11.6%)
Network29 (67.4%)
Unknown8 (18.6%)
Physical1 (2.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (69.8%)
High5 (11.6%)
Unknown8 (18.6%)
User Interaction
None28 (65.1%)
Unknown8 (18.6%)
Required7 (16.3%)
Privileges Required
Low16 (37.2%)
High3 (7.0%)
None16 (37.2%)
Unknown8 (18.6%)

Top CVEs

Signals from CVEs in this product scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-F
Jan 14, 20199.932NONO
IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim t
Nov 20, 20198.828NONO
IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted
Sep 28, 20178.828NONO
IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they should not have access to. IBM X-Force ID: 200015
May 20, 20218.827NONO
IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communicati
Feb 4, 20209.827NONO
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Forc
Jan 14, 20197.526NONO
IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be automatically processed within the e
Jun 8, 20188.826NONO
IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected ar
Sep 28, 20178.626NONO
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that c
Sep 18, 20178.826NONO
IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801.
Sep 25, 20177.825NONO

Exploit Exposure

Signals from CVEs in this product scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (43 CVEs).

Media Mentions

Signals from CVEs in this product scope (43 CVEs).

Top CNAs Publishing CVEs For Security Identity Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.0.266.91.1%00
7.0.1.417.80.4%00
7.0.1.317.80.4%00
7.0.1.217.80.4%00
7.0.1.117.80.4%00
7.0.1.037.30.6%00
7.0.147.11.4%00
7.0.0.337.30.6%00
7.0.0.237.30.6%00
7.0.0.137.30.6%00
7.0.0.068.01.3%00
7.076.61.1%00
6.0.256.41.1%00
6.0.0.617.12.4%00
6.0.0.517.12.4%00
6.0.0.428.01.7%00
6.0.0.385.12.1%00
6.0.0.2017.12.4%00
6.0.0.285.12.1%00
6.0.0.1917.12.4%00