IBM Security Access Manager Container是美国国际商业机器(IBM)公司的一种容器化的身份和访问管理解决方案。 IBM Security Access Manager Container 存在代码问题漏洞,该漏洞源于处理 XML 数据时容易受到 XML 外部实体注入 (XXE) 攻击。远程攻击者可以利用此漏洞暴露敏感信息或消耗内存资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Security Verify Access Appliance | 10.0.0.0 ~ 10.0.6.1 | - |
|
| IBM | Security Verify Access Docker | 10.0.0.0 ~ 10.0.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-31004 | 8.3 HIGH | IBM Security Access Manager Container gain access |
| CVE-2023-30999 | 7.5 HIGH | IBM Security Access Manager denial of service |
| CVE-2023-43016 | 7.3 HIGH | IBM Security Access Manager Container unauthorized access |
| CVE-2023-31006 | 6.5 MEDIUM | IBM Security Access Manager Container denial of service |
| CVE-2023-32329 | 6.2 MEDIUM | IBM Security Access Manager Container improper file validation |
| CVE-2023-31005 | 6.2 MEDIUM | IBM Security Access Manager Container privilege escalation |
No comments yet