|
196721
|
7.5 |
HIGH
Network
|
ibm
|
curam_social_program_management
|
A path traversal vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could allow a remote attacker to traverse directories on the system. An attacker could send a spe…
|
CWE-22
Path Traversal
|
CVE-2020-4776
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196722
|
5.4 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnerability allows attackers to inject malicious scripts into web applications for t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4775
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196723
|
5.4 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling of user-supplied input. By sending a specially-crafted input, a remote attacker…
|
CWE-91
Blind XPath Injection
|
CVE-2020-4774
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196724
|
6.5 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a user to execute unwanted actions on the web applica…
|
CWE-352
Origin Validation Error
|
CVE-2020-4773
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196725
|
8.1 |
HIGH
Network
|
ibm
|
curam_social_program_management
|
An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit this vulnerability to expose sensitive informatio…
|
CWE-611
XXE
|
CVE-2020-4772
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196726
|
5.3 |
MEDIUM
Adjacent
|
ibm
|
security_access_manager security_verify_access
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-4699
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196727
|
5.3 |
MEDIUM
Adjacent
|
ibm
|
security_access_manager security_verify_access
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-4661
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196728
|
5.3 |
MEDIUM
Adjacent
|
ibm
|
security_access_manager security_verify_access
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-4660
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196729
|
5.3 |
MEDIUM
Network
|
sonicwall
|
sonicos sonicosv
|
SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-5143
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196730
|
6.1 |
MEDIUM
Network
|
sonicwall
|
sonicos sonicosv
|
A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to store and potentially execute arbitrary JavaScript code in t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5142
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|