Security Privileged Identity Manager

Vendor:

First CVE: Nov 24, 2016 · Active for 9 years

20
Total CVEs
More Total CVEs than 95% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Privileged Identity Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 24, 2016
9 years ago
Most Recent CVE
Apr 2, 2019
2,674 days ago

CVE Severity & Scoring

Security Privileged Identity Manager20 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local2 (10.0%)
Network18 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (85.0%)
High3 (15.0%)
Unknown0 (0.0%)
User Interaction
None19 (95.0%)
Unknown0 (0.0%)
Required1 (5.0%)
Privileges Required
Low10 (50.0%)
High0 (0.0%)
None10 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account creden
Feb 1, 20179.830NONO
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-cra
Apr 2, 20198.828NONO
IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted
Sep 28, 20178.828NONO
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized act
Apr 2, 20198.827NONO
IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected ar
Sep 28, 20178.626NONO
IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL m
Feb 1, 20177.525NONO
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL
Apr 2, 20197.524NONO
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to comprom
Apr 2, 20197.523NONO
IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, allows remote authenticated users to append to arbitrary files via unspecified vector
Nov 24, 20166.523NONO
IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that would be automatically executed by the server.
Feb 1, 20176.322NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Security Privileged Identity Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.1.176.41.7%00
2.1.014.31.3%00
2.166.21.0%00
2.0.2116.81.3%00
2.0.146.91.7%00
2.0.036.31.7%00
2.026.21.1%00