CVE-2016-9703: IBM Security Identity Manager Virtual Appliance

Low severity, CVSS 2.4. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized user with physical access to the work station to obtain sensitive information.

Affected products

  • IBM Security Identity Manager Virtual Appliance: version 7.0.0.0 only; version 7.0.0.1 only; version 7.0.0.2 only; version 7.0.0.3 only; version 7.0.1.0 only; version 7.0.1.1 only; …

Published 2017-02-01. Last modified 2026-06-17.