Latest CVE Feed
-
6.5
MEDIUMCVE-2021-29714
IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation. IBM X-Force ID: 200968.... Read more
Affected Products : content_navigator- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29713
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ... Read more
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-29712
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a ... Read more
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-29711
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 6.2.7.8 , 6.2.7.9, 7.0.3.0, 7.0.4.0, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2 could allow an authenticated user with certain permissions to initiate an agent upgrade through the CLI interface. IBM X-Forc... Read more
Affected Products : urbancode_deploy- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2021-29708
IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to elevate their privileges. IBM X-Force ID: 200883.... Read more
Affected Products : spectrum_scale- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2021-29707
IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879.... Read more
Affected Products : hardware_management_console- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-29706
IBM AIX 7.1 could allow a non-privileged local user to exploit a vulnerability in the trace facility to expose sensitive information or cause a denial of service. IBM X-Force ID: 200663.... Read more
Affected Products : aix- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29704
IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.... Read more
Affected Products : resilient_security_orchestration_automation_and_response- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29703
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659.... Read more
- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29702
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.... Read more
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29701
IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the sys... Read more
- Published: Jan. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-29700
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sensitive information from configuration files that could aid in further attacks against the system. IBM X-Force ID: 200656.... Read more
Affected Products : sterling_b2b_integrator- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-29699
IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excuted by an user. IBM X-Force ID: 200600.... Read more
Affected Products : docker security_access_manager security_verify_access security_verify_access_docker- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-29697
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to obtain sensitive information through HTTP requests that could be used in further attacks against the system.... Read more
Affected Products : cloud_pak_for_security- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-29696
IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.... Read more
Affected Products : cloud_pak_for_security- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-29695
IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request that would allow them to delete arbitrary files on the system. IBM X-Force ID: 200558.... Read more
Affected Products : 8335-gca_firmware 8335-gta_firmware 8335-gtb_firmware 8335-gca 8335-gta 8335-gtb- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29694
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258.... Read more
- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-29693
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial of service due to a vulnerability in the lpd daemon. IBM X-Force ID: 200255.... Read more
- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-29692
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using ... Read more
- Published: May. 20, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-29691
IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: ... Read more
- Published: May. 20, 2021
- Modified: Nov. 21, 2024