First published: Mon Jul 29 2019(Updated: )
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oneidentity Cloud Access Manager | =8.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13498 is a vulnerability in One Identity Cloud Access Manager 8.1.3 that allows man-in-the-middle (MITM) attacks due to the lack of HTTP Strict Transport Security (HSTS) usage.
The severity of CVE-2019-13498 is high, with a CVSS score of 7.4.
CVE-2019-13498 affects One Identity Cloud Access Manager 8.1.3 by leaving it vulnerable to man-in-the-middle (MITM) attacks.
To fix CVE-2019-13498, update One Identity Cloud Access Manager to version 8.1.4, which includes the fix for this vulnerability.
More information about CVE-2019-13498 can be found in the GitHub repository and the release notes of One Identity Cloud Access Manager 8.1.4.