Latest CVE Feed
-
5.1
MEDIUMCVE-2021-29763
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could allow a local user to keep running a procedure that could cause the system to run out of memory.and cause a denial of service. IBM X-Forc... Read more
- EPSS Score: %0.06
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29761
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information from the dashboard that they should not have access to. IBM X-Force ID: 202265.... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.12
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29760
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to download unauthorized files through the dashboard user interface. IBM X-Force ID: 202213.... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.12
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-29759
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, and 1.3 could allow a privileged user to obtain sensitive information from internal log files. IBM X-Force ID: 202212.... Read more
Affected Products : app_connect_enterprise_certified_container- EPSS Score: %0.04
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29758
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform actions that they should not be able to access due to improper access controls. IBM X-Force ID: 202169.... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.13
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-29757
IBM QRadar User Behavior Analytics 4.1.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202168.... Read more
Affected Products : qradar_user_behavior_analytics- EPSS Score: %0.11
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-29756
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202... Read more
- EPSS Score: %0.16
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29755
IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.... Read more
- EPSS Score: %0.13
- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-29754
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.... Read more
- EPSS Score: %0.21
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-29753
IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.... Read more
- EPSS Score: %0.07
- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-29752
IBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage credentials to privileged users under specific conditions. IBM X-Fporce ID: 201780.... Read more
Affected Products : db2- EPSS Score: %0.36
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29751
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779.... Read more
- EPSS Score: %0.22
- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29750
IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201778.... Read more
- EPSS Score: %0.11
- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29749
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumerat... Read more
- EPSS Score: %0.24
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29747
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authentication mechanism. IBM X-Force ID: 201775.... Read more
- EPSS Score: %0.27
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-29745
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: 201695.... Read more
- EPSS Score: %0.24
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29744
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
- EPSS Score: %0.22
- Published: Aug. 27, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-29743
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more
- EPSS Score: %0.20
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-29742
IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the system. IBM X-Force ID: 201483.... Read more
Affected Products : docker security_access_manager security_verify_access security_verify_access_docker- EPSS Score: %0.20
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2021-29741
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 201478.... Read more
- EPSS Score: %0.04
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024