CVE-2019-13498: Oneidentity Cloud Access Manager

High severity, CVSS 7.4. EPSS: 1.2% chance of exploitation in the next 30 days.

One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

Affected products

Published 2019-07-29. Last modified 2026-06-17.