CVE-2016-5919: IBM Security Access Manager 9.0 Firmware

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Reference #: 1996868.

Affected products

  • IBM Security Access Manager 9.0 Firmware: any version
  • IBM Security Access Manager For Mobile: any version
  • IBM Security Access Manager For Web 7.0 Firmware: any version
  • IBM Security Access Manager For Web 8.0 Firmware: any version

Published 2017-02-16. Last modified 2026-06-17.