|
196671
|
4.9 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be vulnerable to path traversal attacks. IBM X-Force ID: 192905.
|
CWE-22
Path Traversal
|
CVE-2020-4993
|
2024-11-21 14:33 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196672
|
9.8 |
CRITICAL
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. …
|
NVD-CWE-noinfo
|
CVE-2020-4979
|
2024-11-21 14:33 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196673
|
7.8 |
HIGH
Local
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-4932
|
2024-11-21 14:33 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196674
|
5.4 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4929
|
2024-11-21 14:33 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196675
|
6.5 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 could disclose sensitive information about other domains which could be used in further attacks against the system. IBM X-Force ID: 190907.
|
NVD-CWE-noinfo
|
CVE-2020-4883
|
2024-11-21 14:33 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196676
|
5.4 |
MEDIUM
Network
|
ibm
|
flashsystem_900_firmware
|
The IBM FlashSystem 900 user management GUI is vulnerable to stored cross-site scripting in code versions 1.5.2.8 and prior and 1.6.1.2 and prior. This vulnerability allows users to embed arbitrary J…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4987
|
2024-11-21 14:33 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196677
|
6.0 |
MEDIUM
Local
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input validation. IBM X-Force ID: 192541.
|
CWE-20
Improper Input Validation
|
CVE-2020-4981
|
2024-11-21 14:33 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196678
|
7.5 |
HIGH
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_engineering_lifecycle_manager rhapsody_model_manager collaborative_lifecycle_management engineering_test_management engineeri…
|
IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4965
|
2024-11-21 14:33 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196679
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_engineering_lifecycle_manager rhapsody_model_manager collaborative_lifecycle_management engineering_test_management engineeri…
|
IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. …
|
NVD-CWE-noinfo
|
CVE-2020-4964
|
2024-11-21 14:33 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196680
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_engineering_lifecycle_manager rhapsody_model_manager collaborative_lifecycle_management engineering_test_management engineeri…
|
IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality …
|
CWE-79
Cross-site Scripting
|
CVE-2020-4920
|
2024-11-21 14:33 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|