IBM Security Identity Governance and Intelligence(IGI)是美国IBM公司的一套身份治理解决方案。该产品包括生命周期管理、访问风险评估和身份认证管理等功能。 IBM Security IGI中存在授权问题漏洞,该漏洞该源于Security Identity Governance Virtual Appliance没有对授权令牌或会话cookie设置安全属性。攻击者可通过发送http:// link链接或向网站放入该链接利用该漏洞获取cookie值。以下版本
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Security Identity Governance and Intelligence | 5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-1944 | IBM Security Identity Governance and Intelligence 信任管理问题漏洞 | |
| CVE-2018-1945 | IBM Security Identity Governance and Intelligence 输入验证错误漏洞 | |
| CVE-2018-1946 | IBM Security Identity Governance and Intelligence 加密问题漏洞 | |
| CVE-2018-1947 | IBM Security Identity Governance and Intelligence 跨站脚本漏洞 | |
| CVE-2018-1949 | IBM Security Identity Governance and Intelligence 信息泄露漏洞 | |
| CVE-2018-1950 | IBM Security Identity Governance and Intelligence 信息泄露漏洞 | |
| CVE-2018-2006 | IBM Robotic Process Automation with Automation Anywhere 路径遍历漏洞 |
No comments yet