CVE-2019-4156: Medium severity oracle access manager vulnerability
Published Jun 25, 2019
·Updated
IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158572.
Affected Software
1 affected component
IBM Security Access Manager>=9.0.1<=9.0.6
Remediation
Patch Available
Event History
Jun 25, 2019
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for IBM Security Access Manager?
The vulnerability ID for IBM Security Access Manager is CVE-2019-4156.
2
What is the severity of CVE-2019-4156?
The severity of CVE-2019-4156 is medium with a CVSS score of 5.9.
3
Which versions of IBM Security Access Manager are affected by CVE-2019-4156?
IBM Security Access Manager versions 9.0.1 through 9.0.6 are affected by CVE-2019-4156.
4
What is the impact of CVE-2019-4156?
CVE-2019-4156 allows an attacker to decrypt highly sensitive information.
5
How can I fix CVE-2019-4156?
To fix CVE-2019-4156, update IBM Security Access Manager to a version higher than 9.0.6 that uses stronger cryptographic algorithms.