
Cloud Vulnerability DB
A community-led vulnerabilities database
IBM Security Access Manager Appliance vulnerability (CVE-2020-4661) allows attackers to obtain sensitive information using timing side channel attacks, which could aid in further attacks against the system. The vulnerability affects IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 (IBM Security Bulletin).
The vulnerability has a CVSS Base score of 5.3 with a vector of CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating adjacent network attack vector, high attack complexity, no privileges required, no user interaction needed, unchanged scope, high confidentiality impact, and no impact on integrity or availability (IBM Security Bulletin).
If exploited, this vulnerability could allow attackers to obtain sensitive information through timing side channel attacks. This information could potentially be used to facilitate further attacks against the affected system (IBM Security Bulletin).
The vulnerability requires an adjacent network position and high attack complexity to exploit. No privileges or user interaction are required for exploitation (IBM Security Bulletin).
IBM has released fixes for the affected products: IBM Security Access Manager 9.0.7.2 (fix pack: 9.0.7-ISS-ISAM-FP0002) and IBM Security Verify Access 10.0.0.1 (fix pack: 10.0.0-ISS-ISVA-FP0001). For Docker users, updated images can be pulled using specific commands: 'docker pull ibmcom/isam:9.0.7.2' for ISAM and 'docker pull ibmcom/verify-access:10.0.0.1' for ISVA. No workarounds are available (IBM Security Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."