
Cloud Vulnerability DB
A community-led vulnerabilities database
IBM Security Access Manager (ISAM) version 9.0.7.1 contained a security bypass vulnerability that allows authenticated users to manipulate id_token claims without verification. The vulnerability was assigned CVE-2020-4461 and IBM X-Force ID: 181481. The issue was discovered and reported by Dries Eestermans (nynox-dries) (IBM Security Bulletin).
The vulnerability has been assigned a CVSS Base score of 6.5 with the following vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N. This indicates that the vulnerability requires network access and low privileges to exploit, requires no user interaction, and can result in high impact to integrity while not affecting confidentiality or availability (IBM Security Bulletin).
The vulnerability could allow an authenticated user to bypass security mechanisms by manipulating id_token claims without proper verification. This could potentially lead to unauthorized access or privilege escalation within the ISAM system (IBM Security Bulletin).
The vulnerability requires network access and low privileges to exploit. No user interaction is needed for exploitation. However, there are no public reports of this vulnerability being exploited in the wild (IBM Security Bulletin).
IBM has released a fix for this vulnerability in IBM Security Access Manager 9.0.7.1 through patch 9.0.7.1-ISS-ISAM-IF0005 (APAR IIJ24832). No workarounds or alternative mitigations are available, making it crucial for affected users to apply the security update (IBM Security Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."