📦

cloud_access_manager

Vendor: oneidentity

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 0 Remote Access
Total CVEs 3 Total Indexed
Avg. EPSS 0.93% Exploit Prob.
Latest CVE CVE-2019-13497 Nov 04

Security Vulnerability Index

Page 1 / 1
6.5 CVSS

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

EPSS: 0.73%
8.1 CVSS
CVE-2019-13496
Exploit Found

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.

EPSS: 0.85%
7.4 CVSS
CVE-2019-13498
Exploit Found

One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

EPSS: 1.22%