CVE-2018-1813: IBM Security Access Manager

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 150017.

Affected products

  • IBM Security Access Manager: from 9.0.1.0, up to and including 9.0.5.0

Published 2018-12-13. Last modified 2026-06-17.