Latest CVE Feed
-
6.5
MEDIUMCVE-2021-20432
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM... Read more
- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20431
IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an an attacker to obtain sensitive information from the system. IBM X-Force ID: 196342.... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20430
IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks ... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20429
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cross-domain policy. IBM X-Force ID: 196334.... Read more
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20428
IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196315.... Read more
- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20427
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314.... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20426
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.... Read more
- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20424
IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. X-Force ID: 196309.... Read more
Affected Products : cloud_pak_for_applications- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20423
IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper application permissions. IBM X-Force ID: 196308.... Read more
Affected Products : cloud_pak_for_applications- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20422
IBM Cloud Pak for Applications 4.3 could disclose sensitive information to a malicious attacker by accessing data stored in memory. IBM X-Force ID: 196304.... Read more
Affected Products : cloud_pak_for_applications- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20421
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitat... Read more
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20420
IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further attacks against the system. IBM X-Force ID: 196281.... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20419
IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.... Read more
- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20418
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20417
IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ... Read more
Affected Products : guardium_data_encryption- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20416
IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from t... Read more
Affected Products : guardium_data_encryption- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20415
IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217.... Read more
Affected Products : guardium_data_encryption- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-20414
IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly limiting the number of interactions. IBM X-Force ID: 196216.... Read more
Affected Products : guardium_data_encryption- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
5.0
MEDIUMCVE-2021-20413
IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ... Read more
Affected Products : guardium_data_encryption- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20412
IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024