|
194211
|
4.3 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensitive information from the dashboard that they should not have access to. IBM X-Fo…
|
NVD-CWE-noinfo
|
CVE-2021-29761
|
2024-11-21 15:01 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194212
|
4.3 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to download unauthorized files through the dashboard user interface. IBM X-Force ID: 202213.
|
NVD-CWE-noinfo
|
CVE-2021-29760
|
2024-11-21 15:01 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194213
|
4.3 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform actions that they should not be able to access due to improper access controls. IBM X…
|
NVD-CWE-Other
|
CVE-2021-29758
|
2024-11-21 15:01 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194214
|
7.5 |
HIGH
Network
|
ibm
|
cloud_pak_for_security
|
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-29894
|
2024-11-21 15:01 |
2021-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194215
|
5.4 |
MEDIUM
Network
|
ibm
|
business_process_manager business_automation_workflow
|
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3,20.0.0.1, 20.0.0.2, and 21.0.2 and IBM Business Process Manager 8.5 and 8.6 are vulnerable to stored cross-…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29834
|
2024-11-21 15:01 |
2021-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194216
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
A buffer overflow vulnerability in WPG+0x1dda of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted WPG file.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-29367
|
2024-11-21 15:01 |
2021-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194217
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
A buffer overflow vulnerability in FORMATS!GetPlugInInfo+0x2de9 of Irfanview 4.57 allows attackers to execute arbitrary code via a crafted RLE file.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-29366
|
2024-11-21 15:01 |
2021-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194218
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_for_service_management
|
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29905
|
2024-11-21 15:01 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194219
|
5.5 |
MEDIUM
Local
|
ibm
|
jazz_for_service_management
|
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-29904
|
2024-11-21 15:01 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194220
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_for_service_management
|
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29833
|
2024-11-21 15:01 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|