|
197011
|
7.8 |
HIGH
Local
|
ibm
|
aspera_connect
|
IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to o…
|
CWE-426
Untrusted Search Path
|
CVE-2020-4545
|
2024-11-21 14:32 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197012
|
6.5 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails that contain malicious URLs. IBM X-Force …
|
NVD-CWE-noinfo
|
CVE-2020-4337
|
2024-11-21 14:32 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197013
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_collaborative_lifecycle_management rational_doors_next_generation rational_engineering_lifecycle_manager doors_next engineeri…
|
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4546
|
2024-11-21 14:32 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197014
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_collaborative_lifecycle_management rational_doors_next_generation rational_engineering_lifecycle_manager doors_next engineeri…
|
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4522
|
2024-11-21 14:32 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197015
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_collaborative_lifecycle_management rational_doors_next_generation rational_engineering_lifecycle_manager doors_next engineeri…
|
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4445
|
2024-11-21 14:32 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197016
|
5.5 |
MEDIUM
Local
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device w…
|
CWE-88
Argument Injection
|
CVE-2020-4492
|
2024-11-21 14:32 |
2020-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197017
|
3.3 |
LOW
Local
|
ibm
|
spectrum_protect_server
|
IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted c…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-4591
|
2024-11-21 14:32 |
2020-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197018
|
7.5 |
HIGH
Network
|
ibm
|
spectrum_protect
|
IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force ID: 183613.
|
CWE-20
Improper Input Validation
|
CVE-2020-4559
|
2024-11-21 14:32 |
2020-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197019
|
7.2 |
HIGH
Network
|
ibm
|
security_guardium_insights
|
IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other wea…
|
CWE-269
Improper Privilege Management
|
CVE-2020-4603
|
2024-11-21 14:32 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197020
|
6.1 |
MEDIUM
Network
|
ibm
|
websphere_virtual_enterprise websphere_application_server
|
IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.
|
CWE-79
Cross-site Scripting
|
CVE-2020-4575
|
2024-11-21 14:32 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|