Latest CVE Feed
-
4.9
MEDIUMCVE-2021-29728
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of intern... Read more
Affected Products : linux_kernel aix sterling_external_authentication_server sterling_secure_proxy hp-ux solaris windows linux_on_ibm_z- EPSS Score: %0.09
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-29727
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 201106.... Read more
- EPSS Score: %0.04
- Published: Aug. 26, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-29726
IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associated with the host due to improper validation of certificates. IBM X-Force ID: 201104.... Read more
- EPSS Score: %0.07
- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29725
IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.... Read more
Affected Products : linux_kernel aix sterling_secure_proxy solaris windows secure_external_authentication_server- EPSS Score: %2.03
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29723
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100.... Read more
Affected Products : linux_kernel aix sterling_external_authentication_server sterling_secure_proxy hp-ux solaris windows linux_on_ibm_z- EPSS Score: %0.14
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29722
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095.... Read more
Affected Products : linux_kernel aix sterling_external_authentication_server sterling_secure_proxy hp-ux solaris windows linux_on_ibm_z- EPSS Score: %0.14
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-29719
IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091... Read more
- EPSS Score: %0.20
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29716
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.... Read more
- EPSS Score: %0.36
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-29715
IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open ports. IBM X-Force ID: 201018.... Read more
Affected Products : api_connect- EPSS Score: %0.51
- Published: Aug. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29714
IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968.... Read more
Affected Products : content_navigator- EPSS Score: %0.20
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29713
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ... Read more
- EPSS Score: %0.11
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-29712
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a ... Read more
- EPSS Score: %0.15
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-29711
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2 could allow an authenticated user with certain permissions to initiate an agent upgrade through the CLI interface. IBM X-Forc... Read more
Affected Products : urbancode_deploy- EPSS Score: %0.08
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-29708
IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to elevate their privileges. IBM X-Force ID: 200883.... Read more
Affected Products : spectrum_scale- EPSS Score: %0.05
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2021-29707
IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879.... Read more
Affected Products : hardware_management_console- EPSS Score: %0.04
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-29706
IBM AIX 7.1 could allow a non-privileged local user to exploit a vulnerability in the trace facility to expose sensitive information or cause a denial of service. IBM X-Force ID: 200663.... Read more
Affected Products : aix- EPSS Score: %0.04
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29704
IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.... Read more
Affected Products : resilient_security_orchestration_automation_and_response- EPSS Score: %0.09
- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29703
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659.... Read more
- EPSS Score: %0.64
- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29702
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.... Read more
- EPSS Score: %0.76
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29701
IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the sys... Read more
- EPSS Score: %0.12
- Published: Jan. 11, 2022
- Modified: Nov. 21, 2024