|
196611
|
5.9 |
MEDIUM
Network
|
ibm
|
security_identity_manager
|
IBM Security Identity Governance and Intelligence 5.2.4, 5.2.5, and 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-4970
|
2024-11-21 14:33 |
2022-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196612
|
7.5 |
HIGH
Network
|
ibm
|
datapower_gateway
|
IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests. IBM X-Force ID: 1…
|
NVD-CWE-noinfo
|
CVE-2020-4994
|
2024-11-21 14:33 |
2022-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196613
|
5.3 |
MEDIUM
Network
|
ibm
|
security_identity_governance_and_intelligence
|
IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that could aid in future attacks against the system. IBM X-Force ID: 192208.
|
CWE-200
Information Exposure
|
CVE-2020-4957
|
2024-11-21 14:33 |
2022-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196614
|
8.8 |
HIGH
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicio…
|
CWE-352
Origin Validation Error
|
CVE-2020-4668
|
2024-11-21 14:33 |
2022-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196615
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_team_concert
|
IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 and IBM Rational Team Concert 6.0.6 and 6.0.0.1 could allow an authenticated user to obtain sensitive information about build definitions. IB…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-4989
|
2024-11-21 14:33 |
2022-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196616
|
5.5 |
MEDIUM
Local
|
ibm
|
spectrum_scale
|
A security vulnerability in the Spectrum Scale 5.0 and 5.1 allows a non-root user to overflow the mmfsd daemon with requests and preventing the daemon to service other requests. IBM X-Force ID: 19159…
|
NVD-CWE-noinfo
|
CVE-2020-4925
|
2024-11-21 14:33 |
2022-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196617
|
9.8 |
CRITICAL
Network
|
ibm
|
cognos_controller
|
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.
|
CWE-287
Improper Authentication
|
CVE-2020-4879
|
2024-11-21 14:33 |
2022-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196618
|
9.8 |
CRITICAL
Network
|
ibm
|
cognos_controller
|
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.
|
CWE-863
Incorrect Authorization
|
CVE-2020-4877
|
2024-11-21 14:33 |
2022-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196619
|
8.2 |
HIGH
Network
|
ibm
|
cognos_controller
|
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose …
|
CWE-611
XXE
|
CVE-2020-4876
|
2024-11-21 14:33 |
2022-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196620
|
8.2 |
HIGH
Network
|
ibm
|
cognos_controller
|
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose …
|
CWE-611
XXE
|
CVE-2020-4875
|
2024-11-21 14:33 |
2022-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|