CVE-2019-13498
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13498?
CVE-2019-13498 is a vulnerability in One Identity Cloud Access Manager 8.1.3 that allows man-in-the-middle (MITM) attacks due to the lack of HTTP Strict Transport Security (HSTS) usage.
What is the severity of CVE-2019-13498?
The severity of CVE-2019-13498 is high, with a CVSS score of 7.4.
How does CVE-2019-13498 affect One Identity Cloud Access Manager?
CVE-2019-13498 affects One Identity Cloud Access Manager 8.1.3 by leaving it vulnerable to man-in-the-middle (MITM) attacks.
How can I fix CVE-2019-13498?
To fix CVE-2019-13498, update One Identity Cloud Access Manager to version 8.1.4, which includes the fix for this vulnerability.
Where can I find more information about CVE-2019-13498?
More information about CVE-2019-13498 can be found in the GitHub repository and the release notes of One Identity Cloud Access Manager 8.1.4.