Latest CVE Feed
-
8.8
HIGHCVE-2021-39066
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.... Read more
Affected Products : financial_transaction_manager- EPSS Score: %0.18
- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-39065
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of user-supplied input by the Spectrum Copy Data Management Admin Console login and uploadcertifi... Read more
- EPSS Score: %2.29
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-39064
IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957.... Read more
- EPSS Score: %0.16
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-39063
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-Force... Read more
- EPSS Score: %0.08
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-39059
IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially l... Read more
- EPSS Score: %0.22
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-39058
IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 214617.... Read more
- EPSS Score: %0.11
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-39057
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating oth... Read more
- EPSS Score: %0.12
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39056
The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.... Read more
- EPSS Score: %0.28
- Published: Jan. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-39055
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ... Read more
- EPSS Score: %0.22
- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-39054
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's... Read more
- EPSS Score: %0.08
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-39053
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to obtain sensitive information, caused by the improper handling of requests for Spectrum Copy Data Management Admin Console. By sending a specially-crafted request, a remo... Read more
- EPSS Score: %0.18
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-39052
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523.... Read more
- EPSS Score: %0.51
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-39051
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and po... Read more
- EPSS Score: %0.12
- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-39050
IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 214440.... Read more
Affected Products : i2_analysts_notebook- EPSS Score: %0.06
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-39049
IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 214439.... Read more
Affected Products : i2_analysts_notebook- EPSS Score: %0.06
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-39048
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.... Read more
- EPSS Score: %0.04
- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-39047
IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially le... Read more
- EPSS Score: %0.22
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-39046
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user credentials in plain clear text which can be read by a lprivileged user. IBM X-Force ID: 214346.... Read more
- EPSS Score: %0.14
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-39045
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345.... Read more
- EPSS Score: %0.08
- Published: Sep. 01, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-39044
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.... Read more
Affected Products : financial_transaction_manager- EPSS Score: %0.11
- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024