|
196921
|
7.5 |
HIGH
Network
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 2.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 184800.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4594
|
2024-11-21 14:32 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196922
|
7.7 |
HIGH
Network
|
combodo
|
itop
|
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint for the "excel export" portal functionality is called directly it allows gettin…
|
-
|
CVE-2020-4079
|
2024-11-21 14:32 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196923
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation rational_rhapsody_design_manager rhapsody_model_manager doors_next engineering_workflow_management c…
|
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in furthe…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4544
|
2024-11-21 14:32 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196924
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_doors_next_generation rational_rhapsody_design_manager rhapsody_model_manager doors_next engineering_workflow_management c…
|
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in furthe…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4487
|
2024-11-21 14:32 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196925
|
4.4 |
MEDIUM
Local
|
ibm
|
security_verify_privilege_manager
|
IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensiti…
|
CWE-611
XXE
|
CVE-2020-4606
|
2024-11-21 14:32 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196926
|
5.3 |
MEDIUM
Network
|
ibm
|
websphere_extreme_scale
|
IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer hea…
|
CWE-200
Information Exposure
|
CVE-2020-4336
|
2024-11-21 14:32 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196927
|
5.4 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager
|
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.
|
CWE-384
Session Fixation
|
CVE-2020-4555
|
2024-11-21 14:32 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196928
|
6.5 |
MEDIUM
Local
|
vmware
|
workstation esxi fusion
|
VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundatio…
|
CWE-20
Improper Input Validation
|
CVE-2020-3999
|
2024-11-21 14:32 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196929
|
6.1 |
MEDIUM
Network
|
hcltech
|
domino
|
HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerabil…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4080
|
2024-11-21 14:32 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196930
|
3.6 |
LOW
Local
|
vmware
|
carbon_black_cloud
|
The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sens…
|
NVD-CWE-noinfo
|
CVE-2020-4008
|
2024-11-21 14:32 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|