Latest CVE Feed
-
5.9
MEDIUMCVE-2021-29838
IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using m... Read more
Affected Products : security_guardium_insights- EPSS Score: %0.17
- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-29837
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 2... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.11
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29836
IBM Sterling B2B Integrator Standard Edition 5.2.0.0. through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.22
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-29835
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials... Read more
Affected Products : business_automation_workflow- EPSS Score: %0.21
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-29834
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3,20.0.0.1, 20.0.0.2, and 21.0.2 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed... Read more
- EPSS Score: %0.10
- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-29833
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially... Read more
- EPSS Score: %0.33
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-29832
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially... Read more
- EPSS Score: %0.33
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-29831
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cons... Read more
- EPSS Score: %0.66
- Published: Sep. 21, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29825
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_CMD with LOAD or BACKUP. IBM X-Force ID: 204470.... Read more
- EPSS Score: %0.30
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29824
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have access. IBM X-Force ID: 204468.... Read more
- EPSS Score: %0.22
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29823
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 204465.... Read more
- EPSS Score: %0.18
- Published: Sep. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29822
IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr... Read more
- EPSS Score: %0.21
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29821
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t... Read more
Affected Products : tivoli_netcool\/omnibus_webgui- EPSS Score: %0.35
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29820
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t... Read more
Affected Products : tivoli_netcool\/omnibus_webgui- EPSS Score: %0.40
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29819
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t... Read more
Affected Products : tivoli_netcool\/omnibus_webgui- EPSS Score: %0.40
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29818
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t... Read more
Affected Products : tivoli_netcool\/omnibus_webgui- EPSS Score: %0.35
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29817
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t... Read more
Affected Products : tivoli_netcool\/omnibus_webgui- EPSS Score: %0.35
- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29816
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Forc... Read more
- EPSS Score: %0.09
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-29815
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially... Read more
- EPSS Score: %0.33
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-29814
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially... Read more
- EPSS Score: %0.33
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024