CVE-2020-4461: Medium severity IBM ISAM vulnerability
IBM Security Access Manager Appliance 9.0.7.1 could allow an authenticated user to bypass security by allowing idtoken claims manipulation without verification. IBM X-Force ID: 181481.
Other sources
IBM Security Access Manager could allow an authenticated user to bypass security by allowing idtoken claims manipulation without verification.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue in IBM Security Access Manager?
The vulnerability ID for this security issue in IBM Security Access Manager is CVE-2020-4461.
What is the severity of CVE-2020-4461?
The severity of CVE-2020-4461 is medium, with a severity value of 6.5.
What is the affected software for this vulnerability?
The affected software for this vulnerability is IBM Security Access Manager Appliance 9.0.7.1.
How can an authenticated user bypass security with this vulnerability?
An authenticated user can bypass security by allowing id_token claims manipulation without verification.
Is there a patch available to fix this vulnerability?
Yes, there is a patch available to fix this vulnerability. You can download the patch from IBM's support website.