PT-2020-18102 · Ibm · Ibm Security Verify Access+1

Published

2020-10-15

·

Updated

2021-07-21

·

CVE-2020-4499

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Security Access Manager version 9.0.7 IBM Security Verify Access version 10.0.0
Description The issue allows an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications.
Recommendations For IBM Security Access Manager version 9.0.7, update to a version that includes the fix for this issue. For IBM Security Verify Access version 10.0.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to public Oauth clients until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-4499

Affected Products

Ibm Security Access Manager
Ibm Security Verify Access