|
194051
|
4.3 |
MEDIUM
Network
|
ibm
|
engineering_workflow_management rational_team_concert
|
IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build defin…
|
NVD-CWE-noinfo
|
CVE-2021-29701
|
2024-11-21 15:01 |
2022-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194052
|
8.8 |
HIGH
Network
|
smarty debian fedoraproject
|
smarty debian_linux fedora
|
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code b…
|
-
|
CVE-2021-29454
|
2024-11-21 15:01 |
2022-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194053
|
5.9 |
MEDIUM
Network
|
ibm
|
power_hardware_management_console_\(7063-cr1\)_firmware power_system_cs822lc_\(8005-22n\)_firmware power_system_cs821lc_\(8005-12n\)_firmware power_system_s822lc_\(8001-22c\)_firmware pow…
|
BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communication channel which could allow an attacker to obtai…
|
NVD-CWE-noinfo
|
CVE-2021-29847
|
2024-11-21 15:01 |
2021-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194054
|
8.7 |
HIGH
Network
|
ibm netapp
|
db2 oncommand_insight
|
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-For…
|
CWE-863
Incorrect Authorization
|
CVE-2021-29678
|
2024-11-21 15:01 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194055
|
5.4 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-Force ID: 206212.
|
NVD-CWE-noinfo
|
CVE-2021-29867
|
2024-11-21 15:01 |
2021-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194056
|
8.8 |
HIGH
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted …
|
CWE-352
Origin Validation Error
|
CVE-2021-29756
|
2024-11-21 15:01 |
2021-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194057
|
5.3 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091
|
NVD-CWE-noinfo
|
CVE-2021-29719
|
2024-11-21 15:01 |
2021-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194058
|
6.5 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.
|
NVD-CWE-noinfo
|
CVE-2021-29716
|
2024-11-21 15:01 |
2021-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194059
|
4.3 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-29863
|
2024-11-21 15:01 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194060
|
6.1 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29849
|
2024-11-21 15:01 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|