Security Identity Manager Adapter
Vendor:
First CVE: Jul 15, 2016 · Active for 10 years
9
Total CVEs
More Total CVEs than 88% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Security Identity Manager Adapter over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 15, 2016
10 years ago
Most Recent CVE
Jun 28, 2021
1,856 days ago
CVE Severity & Scoring
Security Identity Manager Adapter9 CVEs
67%
33%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (22.2%)
Network7 (77.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (77.8%)
High2 (22.2%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None5 (55.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20574HIGH IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could | Jun 28, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-20573MEDIUM IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflo | Jun 28, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-20572MEDIUM IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overfl | Jun 28, 2021 | 6.5 | 22 | NO | NO |
CVE-2016-0338MEDIUM IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext passwords by (1) reading a confi | Jul 15, 2016 | 6.2 | 22 | NO | NO |
CVE-2021-20494MEDIUM IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bounds. An authenticared user could overflow the buffer and ca | Jun 28, 2021 | 6.5 | 21 | NO | NO |
CVE-2016-0340HIGH IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allows remote attackers to hijack se | Jul 15, 2016 | 7.4 | 19 | NO | NO |
CVE-2016-0330HIGH IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes it easier for remote attackers | Jul 15, 2016 | 7.3 | 19 | NO | NO |
CVE-2016-0339MEDIUM IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for re | Jul 15, 2016 | 5.6 | 16 | NO | NO |
CVE-2016-0357MEDIUM IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote attackers to conduct clickjacking attacks via a crafted web | Jul 15, 2016 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Security Identity Manager Adapter
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0.1.1 | 5 | 6.2 | 0.9% | 0 | 0 |
| 7.0.1.0 | 5 | 6.2 | 0.9% | 0 | 0 |
| 7.0.0.3 | 5 | 6.2 | 0.9% | 0 | 0 |
| 7.0.0.2 | 5 | 6.2 | 0.9% | 0 | 0 |
| 7.0.0.1 | 5 | 6.2 | 0.9% | 0 | 0 |
| 7.0.0.0 | 9 | 6.6 | 1.2% | 0 | 0 |
| 6.0.0.0 | 4 | 7.1 | 1.5% | 0 | 0 |