← Vulnerability feed

Vulnerability record · CVE-2017-1489 · published 29 August 2017

CVE-2017-1489: Ibm tivoli access manager for e-business open redirect vulnerability

Ibm · Tivoli Access Manager For E Business

IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.

6.1 CVSS 3.0 Medium EPSS 1.2% · top 33.5% CWE-601 · Open redirect
6.1CVSS 3.0 base score, v2 5.8
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-1489 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2018-1722Ibm security access manager vulnerabilityIBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are r…EPSS 9.0%10.0CVE-2014-4823Ibm security access manager for web 7.0 firmware os command injection vulnerabilityThe administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security A…EPSS 2.8%10.0CVE-2014-3073Ibm security access manager for mobile software vulnerabilityUnspecified vulnerability in IBM Security Access Manager (ISAM) for Mobile 8.0 and IBM Security Access Manager for Web 7.0 and 8.0 allows remote atta…EPSS 4.2%9.8CVE-2020-4499Ibm security access manager vulnerabilityIBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the …EPSS 1.2%9.1CVE-2016-3028Ibm security access manager os command injection vulnerabilityIBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authent…EPSS 3.5%8.8CVE-2019-4135Ibm security access manager vulnerabilityIBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated users to impersonate other use…EPSS 1.5%8.1CVE-2016-3025Ibm security access manager vulnerabilityIBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed logi…EPSS 1.6%8.0CVE-2014-3053Ibm security access manager for web 8.0 firmware improper authentication vulnerabilityThe Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Acce…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2017-1489), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.