IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 127394.
2017-09-28T01:29:01.403
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | security_identity_governance_and_intelligence | 5.2.0 | Yes |
Application | ibm | security_identity_governance_and_intelligence | 5.2.1 | Yes |
Application | ibm | security_identity_manager | 6.0.0.0 | Yes |
Application | ibm | security_identity_manager | 7.0.0.0 | Yes |
Application | ibm | security_privileged_identity_manager | 2.0.0 | Yes |
Application | ibm | security_privileged_identity_manager | 2.0.1 | Yes |
Application | ibm | security_privileged_identity_manager | 2.0.2 | Yes |