Latest CVE Feed
-
8.4
HIGHCVE-2021-29740
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker could execute arbitrary code in the context of process memory, potentially escalating their system ... Read more
Affected Products : spectrum_scale- EPSS Score: %0.07
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-29739
IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846.... Read more
Affected Products : planning_analytics_local- EPSS Score: %0.14
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29738
IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumera... Read more
- EPSS Score: %0.16
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29737
IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301.... Read more
- EPSS Score: %0.12
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-29736
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.... Read more
- EPSS Score: %0.68
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29735
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
- EPSS Score: %0.10
- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-29730
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 20116... Read more
Affected Products : infosphere_information_server- EPSS Score: %0.27
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-29728
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of intern... Read more
Affected Products : linux_kernel aix sterling_external_authentication_server sterling_secure_proxy hp-ux solaris windows linux_on_ibm_z- EPSS Score: %0.09
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-29727
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 201106.... Read more
- EPSS Score: %0.04
- Published: Aug. 26, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-29726
IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associated with the host due to improper validation of certificates. IBM X-Force ID: 201104.... Read more
- EPSS Score: %0.07
- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29725
IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.... Read more
Affected Products : linux_kernel aix sterling_secure_proxy solaris windows secure_external_authentication_server- EPSS Score: %2.03
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29723
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-ForceID: 201100.... Read more
Affected Products : linux_kernel aix sterling_external_authentication_server sterling_secure_proxy hp-ux solaris windows linux_on_ibm_z- EPSS Score: %0.14
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29722
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201095.... Read more
Affected Products : linux_kernel aix sterling_external_authentication_server sterling_secure_proxy hp-ux solaris windows linux_on_ibm_z- EPSS Score: %0.14
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-29719
IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091... Read more
- EPSS Score: %0.20
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29716
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.... Read more
- EPSS Score: %0.36
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-29715
IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open ports. IBM X-Force ID: 201018.... Read more
Affected Products : api_connect- EPSS Score: %0.51
- Published: Aug. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29714
IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968.... Read more
Affected Products : content_navigator- EPSS Score: %0.20
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29713
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ... Read more
- EPSS Score: %0.11
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-29712
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a ... Read more
- EPSS Score: %0.15
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-29711
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2 could allow an authenticated user with certain permissions to initiate an agent upgrade through the CLI interface. IBM X-Forc... Read more
Affected Products : urbancode_deploy- EPSS Score: %0.08
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024