|
196711
|
4.3 |
MEDIUM
Network
|
ibm
|
planning_analytics
|
IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's internal structure by exposing sensitive information in HTTP repsonses. IBM X-Forc…
|
CWE-200
Information Exposure
|
CVE-2020-4953
|
2024-11-21 14:33 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196712
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_reporting_service
|
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the int…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4933
|
2024-11-21 14:33 |
2021-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196713
|
4.8 |
MEDIUM
Adjacent
|
ibm
|
spectrum_protect_operations_center
|
IBM Spectrum Protect Operations Center 7.1 and 8.1 is vulnerable to a denial of service, caused by a RPC that allows certain cache values to be set and dumped to a file. By setting a grossly large ca…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-4956
|
2024-11-21 14:33 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196714
|
8.0 |
HIGH
Adjacent
|
ibm
|
spectrum_protect_operations_center
|
IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter validation. By creating an unspecified servlet re…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-4955
|
2024-11-21 14:33 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196715
|
5.4 |
MEDIUM
Adjacent
|
ibm
|
spectrum_protect_operations_center
|
IBM Spectrum Protect Operations Center 7.1 and 8.1 could allow a remote attacker to bypass authentication restrictions, caused by improper session validation . By using the configuration panel to obt…
|
CWE-384
Session Fixation
|
CVE-2020-4954
|
2024-11-21 14:33 |
2021-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196716
|
5.4 |
MEDIUM
Network
|
ibm
|
business_automation_workflow case_manager
|
IBM Case Manager 5.2 and 5.3 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in th…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4768
|
2024-11-21 14:33 |
2021-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196717
|
7.5 |
HIGH
Network
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to excess resource consumption. IBM X-Force ID: 193659.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-5023
|
2024-11-21 14:33 |
2021-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196718
|
5.5 |
MEDIUM
Local
|
ibm
|
security_identity_governance_and_intelligence
|
IBM Security Identity Governance and Intelligence 5.2.6 could allow a local user to obtain sensitive information via the capturing of screenshots of authentication credentials. IBM X-Force ID: 192913.
|
NVD-CWE-Other
|
CVE-2020-4996
|
2024-11-21 14:33 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196719
|
5.3 |
MEDIUM
Network
|
ibm
|
security_identity_governance_and_intelligence
|
IBM Security Identity Governance and Intelligence 5.2.6 does not invalidate session after logout which could allow a user to obtain sensitive information from another users' session. IBM X-Force ID: …
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-4995
|
2024-11-21 14:33 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196720
|
8.2 |
HIGH
Network
|
ibm
|
security_identity_governance_and_intelligence
|
IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information to an unauthorized user using a specially crafted HTTP request. IBM X-Force ID: 189446.
|
NVD-CWE-noinfo
|
CVE-2020-4795
|
2024-11-21 14:33 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|