CVE-2016-9703

IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.4 LOW
PHYSICAL
LOW
NONE
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
ibmsecurity_identity_manager_virtual_appliance
7.0.0.0
ibmsecurity_identity_manager_virtual_appliance
7.0.0.1
ibmsecurity_identity_manager_virtual_appliance
7.0.0.2
ibmsecurity_identity_manager_virtual_appliance
7.0.0.3
ibmsecurity_identity_manager_virtual_appliance
7.0.1.0
ibmsecurity_identity_manager_virtual_appliance
7.0.1.1
ibmsecurity_identity_manager_virtual_appliance
7.0.1.2
ibmsecurity_identity_manager_virtual_appliance
7.0.1.3
ibmsecurity_identity_manager_virtual_appliance
7.0.1.4
𝑥
= Vulnerable software versions