Latest CVE Feed
-
6.5
MEDIUMCVE-2021-20464
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.... Read more
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20461
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force... Read more
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-20454
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.... Read more
Affected Products : websphere_application_server- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-20453
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM ... Read more
Affected Products : websphere_application_server- Published: Apr. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20448
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se... Read more
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20447
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20446
IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20445
IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. IBM X-Force ID: 196621.... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20444
IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20443
IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere. IBM X-Force ID: 196619.... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20442
IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196618.... Read more
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-20441
IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196617.... Read more
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-20440
IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recepient. An attacker who is a valid user in the user registry used by API Manager can use a stolen invitation link and register themselves... Read more
Affected Products : api_connect- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20439
IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.... Read more
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-20435
IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 196355.... Read more
Affected Products : security_verify_bridge- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-20434
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 196346.... Read more
Affected Products : security_verify_bridge- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20433
IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 196345.... Read more
- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20432
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM... Read more
- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20431
IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an an attacker to obtain sensitive information from the system. IBM X-Force ID: 196342.... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20430
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks ... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024