|
196811
|
3.3 |
LOW
Local
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-4906
|
2024-11-21 14:33 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196812
|
5.9 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an remote attacker to obtain sensitive information, caused by a man in the middle attack. By SSL striping, an…
|
NVD-CWE-noinfo
|
CVE-2020-4905
|
2024-11-21 14:33 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196813
|
6.5 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions t…
|
CWE-352
Origin Validation Error
|
CVE-2020-4904
|
2024-11-21 14:33 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196814
|
6.1 |
MEDIUM
Network
|
ibm
|
sterling_file_gateway
|
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fu…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4658
|
2024-11-21 14:33 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196815
|
6.1 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alter…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4657
|
2024-11-21 14:33 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196816
|
7.5 |
HIGH
Network
|
dell oracle
|
bsafe_micro-edition-suite http_server security_service database weblogic_server_proxy_plug-in
|
Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability resulting i…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-5360
|
2024-11-21 14:33 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196817
|
5.8 |
MEDIUM
Network
|
dell oracle
|
bsafe_micro-edition-suite database weblogic_server_proxy_plug-in
|
Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to mo…
|
CWE-252
Unchecked Return Value
|
CVE-2020-5359
|
2024-11-21 14:33 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196818
|
6.1 |
MEDIUM
Network
|
ibm
|
tivoli_netcool\/impact
|
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vul…
|
CWE-601
Open Redirect
|
CVE-2020-4849
|
2024-11-21 14:33 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196819
|
9.8 |
CRITICAL
Network
|
ibm
|
connect\
|
IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516.
|
CWE-287
Improper Authentication
|
CVE-2020-4747
|
2024-11-21 14:33 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196820
|
8.8 |
HIGH
Network
|
ibm
|
resilient_security_orchestration_automation_and_response
|
IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.
|
CWE-20 CWE-1236
Improper Input Validation Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-4633
|
2024-11-21 14:33 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|