CVE-2019-13497: Oneidentity Cloud Access Manager

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

Affected products

  • Oneidentity Cloud Access Manager: before 8.1.4 (fixed in 8.1.4); version 8.1.4 only

Published 2019-11-04. Last modified 2026-06-17.