|
196701
|
8.2 |
HIGH
Network
|
sonicwall
|
directory_services_connector
|
SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privilege…
|
CWE-287
Improper Authentication
|
CVE-2020-5148
|
2024-11-21 14:33 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196702
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation doors_next engineering_workflow_management engineering_test_management engineering_lifecycle_management…
|
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially …
|
CWE-79
Cross-site Scripting
|
CVE-2020-4975
|
2024-11-21 14:33 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196703
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation doors_next engineering_workflow_management engineering_test_management engineering_lifecycle_management…
|
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially …
|
CWE-79
Cross-site Scripting
|
CVE-2020-4866
|
2024-11-21 14:33 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196704
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation doors_next engineering_workflow_management engineering_test_management engineering_lifecycle_management…
|
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4863
|
2024-11-21 14:33 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196705
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation doors_next engineering_workflow_management engineering_test_management engineering_lifecycle_management…
|
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4857
|
2024-11-21 14:33 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196706
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation doors_next engineering_workflow_management engineering_test_management engineering_lifecycle_management…
|
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4856
|
2024-11-21 14:33 |
2021-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196707
|
3.3 |
LOW
Local
|
ibm
|
cloud_application_performance_management
|
The IBM Application Performance Monitoring UI (IBM Cloud APM 8.1.4) allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 187975.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-4726
|
2024-11-21 14:33 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196708
|
3.5 |
LOW
Network
|
ibm
|
cloud_application_performance_management
|
IBM Monitoring (IBM Cloud APM 8.1.4 ) could allow an authenticated user to modify HTML content by sending a specially crafted HTTP request to the APM UI, which could mislead another user. IBM X-Force…
|
NVD-CWE-Other
|
CVE-2020-4725
|
2024-11-21 14:33 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196709
|
4.9 |
MEDIUM
Network
|
ibm
|
cloud_application_performance_management
|
The IBM Cloud APM 8.1.4 server will issue a DNS request to resolve any hostname specified in the Cloud Event Management Webhook URL configuration definition. This could enable an authenticated user w…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-4719
|
2024-11-21 14:33 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196710
|
6.5 |
MEDIUM
Network
|
ibm
|
mq
|
IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM X-Force ID: 191747.
|
NVD-CWE-noinfo
|
CVE-2020-4931
|
2024-11-21 14:33 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|