Latest CVE Feed
-
9.1
CRITICALCVE-2021-20487
IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing the host firmware signature verification process.... Read more
Affected Products : power9_system_firmware scale-out_lc_system_firmware 9008-22l 9009-22a 9009-41a 9009-42a 9040-mr9 9080-m9s 9223-22h 9223-42h +8 more products- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20486
IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668.... Read more
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20485
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X... Read more
Affected Products : sterling_file_gateway- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20484
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosur... Read more
Affected Products : sterling_file_gateway- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20483
IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197591.... Read more
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-20482
IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. ... Read more
Affected Products : cloud_pak_for_automation- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20481
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosur... Read more
Affected Products : sterling_file_gateway- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20480
IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 1975... Read more
- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20479
IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197498.... Read more
Affected Products : cloud_pak_system- Published: May. 09, 2022
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2021-20478
IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of another user in self service console. IBM X-Force ID: 197497.... Read more
Affected Products : cloud_pak_system- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20477
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : planning_analytics- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20474
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.... Read more
Affected Products : guardium_data_encryption- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20473
IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 196944.... Read more
Affected Products : sterling_file_gateway- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20470
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.... Read more
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20468
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 196825.... Read more
- Published: Sep. 01, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20464
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.... Read more
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20461
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force... Read more
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-20454
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.... Read more
Affected Products : websphere_application_server- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-20453
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM ... Read more
Affected Products : websphere_application_server- Published: Apr. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20448
IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se... Read more
- Published: Apr. 27, 2021
- Modified: Nov. 21, 2024