|
194081
|
5.4 |
MEDIUM
Network
|
ibm
|
security_risk_manager_on_cp4s
|
IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29912
|
2024-11-21 15:01 |
2021-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194082
|
5.4 |
MEDIUM
Network
|
ibm
|
business_automation_workflow
|
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29878
|
2024-11-21 15:01 |
2021-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194083
|
8.8 |
HIGH
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access to the 'New Job' page to which they should not have access to. IBM X-Force ID: …
|
NVD-CWE-noinfo
|
CVE-2021-29745
|
2024-11-21 15:01 |
2021-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194084
|
8.8 |
HIGH
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side inclu…
|
CWE-94
Code Injection
|
CVE-2021-29679
|
2024-11-21 15:01 |
2021-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194085
|
7.8 |
HIGH
Local
|
hitachi
|
it_operations_director job_management_partner_1\/it_desktop_management-manager job_management_partner_1\/it_desktop_management_2-manager job_management_partner_1\/remote_control_agent job…
|
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker …
|
NVD-CWE-noinfo
|
CVE-2021-29645
|
2024-11-21 15:01 |
2021-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194086
|
9.8 |
CRITICAL
Network
|
hitachi
|
it_operations_director job_management_partner_1\/it_desktop_management-manager job_management_partner_1\/it_desktop_management_2-manager job_management_partner_1\/remote_control_agent job…
|
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this is…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-29644
|
2024-11-21 15:01 |
2021-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194087
|
5.5 |
MEDIUM
Local
|
ibm
|
app_connect_enterprise_certified_container
|
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a local user when it is configured to use an IBM Cloud API key to connect to clo…
|
NVD-CWE-noinfo
|
CVE-2021-29906
|
2024-11-21 15:01 |
2021-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194088
|
4.3 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sensitive information from configuration files that could aid in further attacks a…
|
NVD-CWE-noinfo
|
CVE-2021-29700
|
2024-11-21 15:01 |
2021-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194089
|
9.8 |
CRITICAL
Network
|
ibm
|
ts7700_firmware
|
The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrative access to the Management Interface without authe…
|
NVD-CWE-noinfo
|
CVE-2021-29908
|
2024-11-21 15:01 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194090
|
9.8 |
CRITICAL
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to v…
|
CWE-89
SQL Injection
|
CVE-2021-29903
|
2024-11-21 15:01 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|