CVE-2015-5012: IBM Security Access Manager 9.0 Firmware

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

Affected products

  • IBM Security Access Manager 9.0 Firmware: version 9.0.0 only
  • IBM Security Access Manager For Web 7.0 Firmware: version 7.0.0.1 only; version 7.0.0.2 only; version 7.0.0.3 only; version 7.0.0.4 only; version 7.0.0.5 only; version 7.0.0.6 only; …
  • IBM Security Access Manager For Web 8.0 Firmware: version 8.0.0.1 only; version 8.0.0.2 only; version 8.0.0.3 only; version 8.0.0.5 only; version 8.0.1 only; version 8.0.1.0 only; …

Published 2016-02-15. Last modified 2026-06-17.