IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality to unintended actors. IBM X-Force ID: 158574.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.ibm.com/support/docview.wss?uid=ibm10888379 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/158574 | vdb entry vendor advisory |