Latest CVE Feed
-
7.5
HIGHCVE-2021-20474
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.... Read more
Affected Products : guardium_data_encryption- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20473
IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944.... Read more
Affected Products : sterling_file_gateway- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20470
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.... Read more
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20468
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825.... Read more
- Published: Sep. 01, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20464
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.... Read more
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20461
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force... Read more
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-20454
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.... Read more
Affected Products : websphere_application_server- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-20453
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM ... Read more
Affected Products : websphere_application_server- Published: Apr. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20448
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se... Read more
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20447
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20446
IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20445
IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. IBM X-Force ID: 196621.... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20444
IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20443
IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere. IBM X-Force ID: 196619.... Read more
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20442
IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196618.... Read more
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-20441
IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196617.... Read more
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-20440
IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recepient. An attacker who is a valid user in the user registry used by API Manager can use a stolen invitation link and register themselves... Read more
Affected Products : api_connect- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20439
IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.... Read more
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-20435
IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 196355.... Read more
Affected Products : security_verify_bridge- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-20434
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 196346.... Read more
Affected Products : security_verify_bridge- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024