Latest CVE Feed
-
5.9
MEDIUMCVE-2021-29753
IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.... Read more
- EPSS Score: %0.07
- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-29752
IBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage credentials to privileged users under specific conditions. IBM X-Fporce ID: 201780.... Read more
Affected Products : db2- EPSS Score: %0.36
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29751
IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authenticated user to obtain sensitive information about another user under nondefault configurations. IBM X-Force ID: 201779.... Read more
- EPSS Score: %0.22
- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29750
IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201778.... Read more
- EPSS Score: %0.11
- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-29749
IBM Secure External Authentication Server 6.0.2 and IBM Secure Proxy 6.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumerat... Read more
- EPSS Score: %0.24
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29747
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vulnerability in the authentication mechanism. IBM X-Force ID: 201775.... Read more
- EPSS Score: %0.27
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-29745
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: 201695.... Read more
- EPSS Score: %0.24
- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29744
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
- EPSS Score: %0.22
- Published: Aug. 27, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-29743
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more
- EPSS Score: %0.20
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-29742
IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the system. IBM X-Force ID: 201483.... Read more
Affected Products : docker security_access_manager security_verify_access security_verify_access_docker- EPSS Score: %0.20
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2021-29741
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in Korn Shell (ksh) to gain root privileges. IBM X-Force ID: 201478.... Read more
- EPSS Score: %0.04
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2021-29740
IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker could execute arbitrary code in the context of process memory, potentially escalating their system ... Read more
Affected Products : spectrum_scale- EPSS Score: %0.07
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-29739
IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. X-Force ID: 198846.... Read more
Affected Products : planning_analytics_local- EPSS Score: %0.14
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29738
IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumera... Read more
- EPSS Score: %0.16
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29737
IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301.... Read more
- EPSS Score: %0.12
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-29736
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the system. IBM X-Force ID: 201300.... Read more
- EPSS Score: %0.68
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29735
IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
- EPSS Score: %0.10
- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-29730
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 20116... Read more
Affected Products : infosphere_information_server- EPSS Score: %0.27
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-29728
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of intern... Read more
Affected Products : linux_kernel aix sterling_external_authentication_server sterling_secure_proxy hp-ux solaris windows linux_on_ibm_z- EPSS Score: %0.09
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2021-29727
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 201106.... Read more
- EPSS Score: %0.04
- Published: Aug. 26, 2021
- Modified: Nov. 21, 2024