|
197421
|
9.8 |
CRITICAL
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, o…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-20426
|
2024-11-21 14:46 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197422
|
7.5 |
HIGH
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-20419
|
2024-11-21 14:46 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197423
|
7.8 |
HIGH
Local
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-20389
|
2024-11-21 14:46 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197424
|
6.1 |
MEDIUM
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20386
|
2024-11-21 14:46 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197425
|
7.2 |
HIGH
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerabilit…
|
NVD-CWE-noinfo
|
CVE-2021-20385
|
2024-11-21 14:46 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197426
|
5.3 |
MEDIUM
Network
|
ibm
|
control_center
|
IBM Control Center 6.2.0.0 could allow a user to obtain sensitive version information that could be used in further attacks against the system. IBM X-Force ID: 198763.
|
NVD-CWE-noinfo
|
CVE-2021-20529
|
2024-11-21 14:46 |
2021-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197427
|
5.4 |
MEDIUM
Network
|
ibm
|
control_center
|
IBM Control Center 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20528
|
2024-11-21 14:46 |
2021-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197428
|
5.4 |
MEDIUM
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended f…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20374
|
2024-11-21 14:46 |
2021-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197429
|
7.5 |
HIGH
Network
|
mitsubishi
|
gt27_firmware gt25_firmware gt23_firmware gt21_firmware gs21_firmware gt_softgot2000_firmware
|
Buffer access with incorrect length value vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.38.000, GT25 model communication driver versions 01.19.000 thro…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2021-20589
|
2024-11-21 14:46 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197430
|
5.3 |
MEDIUM
Network
|
ibm
|
cloud_pak_for_security
|
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an u…
|
NVD-CWE-Other
|
CVE-2021-20565
|
2024-11-21 14:46 |
2021-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|