1821
|
- |
|
-
|
-
|
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-51547
|
2025-02-6 14:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1822
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user to write to an arbitrary file on the system during bar configuration deployment …
|
CWE-22
Path Traversal
|
CVE-2025-0799
|
2025-02-6 10:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1823
|
9.1 |
CRITICAL
Network
|
-
|
-
|
IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
|
CWE-78
OS Command
|
CVE-2024-51450
|
2025-02-6 10:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1824
|
7.8 |
HIGH
Local
|
-
|
-
|
IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their privileges due to execution with unnecessary privileges.
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2024-49814
|
2025-02-6 10:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1825
|
5.3 |
MEDIUM
Network
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2024-56473
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1826
|
6.4 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering …
|
CWE-79
Cross-site Scripting
|
CVE-2024-56472
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1827
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially le…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-56471
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1828
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially le…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-56470
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1829
|
4.8 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within…
|
CWE-80
Basic XSS
|
CVE-2024-38318
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1830
|
4.8 |
MEDIUM
Network
|
-
|
-
|
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the inten…
|
CWE-79
Cross-site Scripting
|
CVE-2024-38317
|
2025-02-6 08:15 |
2025-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|