|
197101
|
7.5 |
HIGH
Network
|
ibm
|
aspera_high-speed_transfer_server_for_cloud_pak_for_integration aspera_shares_on_demand aspera_server_on_demand aspera_faspex_on_demand aspera_application_platform_on_demand aspera_tra…
|
Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitr…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-4435
|
2024-11-21 14:32 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197102
|
7.5 |
HIGH
Network
|
ibm
|
aspera_high-speed_transfer_server_for_cloud_pak_for_integration aspera_shares_on_demand aspera_server_on_demand aspera_faspex_on_demand aspera_application_platform_on_demand aspera_tra…
|
Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to e…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-4434
|
2024-11-21 14:32 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197103
|
7.5 |
HIGH
Network
|
ibm
|
aspera_high-speed_transfer_server_for_cloud_pak_for_integration aspera_shares_on_demand aspera_server_on_demand aspera_faspex_on_demand aspera_application_platform_on_demand aspera_tra…
|
Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execut…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-4433
|
2024-11-21 14:32 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197104
|
7.5 |
HIGH
Network
|
ibm
|
aspera_high-speed_transfer_server_for_cloud_pak_for_integration aspera_shares_on_demand aspera_server_on_demand aspera_faspex_on_demand aspera_application_platform_on_demand aspera_tra…
|
Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API. …
|
CWE-77
Command Injection
|
CVE-2020-4432
|
2024-11-21 14:32 |
2020-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197105
|
6.1 |
MEDIUM
Network
|
boltcms
|
bolt
|
In Bolt CMS before version 3.7.1, the filename of uploaded files was vulnerable to stored XSS. It is not possible to inject javascript code in the file name when creating/uploading the file. But, onc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4041
|
2024-11-21 14:32 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197106
|
4.3 |
MEDIUM
Network
|
boltcms
|
bolt
|
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorize…
|
-
|
CVE-2020-4040
|
2024-11-21 14:32 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197107
|
7.4 |
HIGH
Network
|
prisma
|
graphql-playground-middleware-hapi graphql-playground-middleware-lambda graphql-playground-middleware-koa graphql-playground-middleware-express graphql-playground-html
|
GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method …
|
-
|
CVE-2020-4038
|
2024-11-21 14:32 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197108
|
7.4 |
HIGH
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially le…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-4529
|
2024-11-21 14:32 |
2020-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197109
|
9.8 |
CRITICAL
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID:…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-4450
|
2024-11-21 14:32 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197110
|
7.5 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-4449
|
2024-11-21 14:32 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|