Latest CVE Feed
-
5.9
MEDIUMCVE-2021-38978
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensit... Read more
Affected Products : linux_kernel aix security_key_lifecycle_manager windows security_guardium_key_lifecycle_manager- EPSS Score: %0.08
- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38977
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site t... Read more
Affected Products : linux_kernel aix security_key_lifecycle_manager windows security_guardium_key_lifecycle_manager- EPSS Score: %0.13
- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-38976
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781.... Read more
Affected Products : linux_kernel aix security_key_lifecycle_manager windows security_guardium_key_lifecycle_manager- EPSS Score: %0.04
- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-38975
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780.... Read more
Affected Products : linux_kernel aix security_key_lifecycle_manager windows security_guardium_key_lifecycle_manager- EPSS Score: %0.10
- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-38974
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause a denial of service using specially crafted HTTP requests. IBM X-Force ID: 212779.... Read more
Affected Products : linux_kernel aix security_key_lifecycle_manager windows security_guardium_key_lifecycle_manager- EPSS Score: %0.24
- Published: Nov. 15, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-38973
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.... Read more
- EPSS Score: %0.18
- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38972
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.... Read more
- EPSS Score: %0.17
- Published: Nov. 12, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-38971
IBM Data Virtualization on Cloud Pak for Data 1.3.0, 1.4.1, 1.5.0, 1.7.1 and 1.7.3 could allow an authorized user to bypass data masking rules and obtain sensitve information. IBM X-Force ID: 212620.... Read more
Affected Products : data_virtualization_on_cloud_pak_for_data- EPSS Score: %0.19
- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38969
IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM X-Force ID: 212609.... Read more
Affected Products : spectrum_virtualize- EPSS Score: %0.19
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-38967
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441.... Read more
Affected Products : mq_appliance- EPSS Score: %0.04
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38966
IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tru... Read more
- EPSS Score: %0.22
- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-38965
IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346.... Read more
Affected Products : filenet_content_manager- EPSS Score: %2.31
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-38961
IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM ... Read more
- EPSS Score: %0.13
- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38960
IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.... Read more
- EPSS Score: %0.22
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-38959
IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of service by writing arbitrary files to admin protected directories on the system. IBM X-Force ID: 212046.... Read more
- EPSS Score: %0.04
- Published: Nov. 17, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38958
IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrency issue. IBM X-Force ID: 212042... Read more
Affected Products : mq_appliance- EPSS Score: %0.04
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-38957
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.... Read more
Affected Products : security_verify_access- EPSS Score: %0.21
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-38956
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive version information in HTTP response headers that could aid in further attacks against the system. IBM X-Force ID: 212038... Read more
Affected Products : security_verify_access- EPSS Score: %0.14
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-38955
IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands. IBM X-Force ID: 211825.... Read more
- EPSS Score: %0.04
- Published: Mar. 01, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-38954
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could disclose sensitive version information that could aid in future attacks against the system. IBM X-Force ID: 211414.... Read more
- EPSS Score: %0.12
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024