|
196801
|
4.9 |
MEDIUM
Network
|
ibm
|
security_secret_server
|
IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in fur…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4842
|
2024-11-21 14:33 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196802
|
5.9 |
MEDIUM
Network
|
ibm
|
security_secret_server
|
IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this …
|
CWE-862
Missing Authorization
|
CVE-2020-4841
|
2024-11-21 14:33 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196803
|
5.4 |
MEDIUM
Network
|
ibm
|
business_process_manager automation_workstream_services business_automation_workflow
|
IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensi…
|
CWE-863
Incorrect Authorization
|
CVE-2020-4794
|
2024-11-21 14:33 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196804
|
6.4 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alteri…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4757
|
2024-11-21 14:33 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196805
|
6.1 |
MEDIUM
Network
|
ibm
|
security_secret_server
|
IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attack…
|
CWE-601
Open Redirect
|
CVE-2020-4840
|
2024-11-21 14:33 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196806
|
6.5 |
MEDIUM
Network
|
ibm
|
planning_analytics
|
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM…
|
CWE-352
Origin Validation Error
|
CVE-2020-4764
|
2024-11-21 14:33 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196807
|
2.7 |
LOW
Network
|
ibm
|
security_key_lifecycle_manager
|
IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information cou…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4846
|
2024-11-21 14:33 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196808
|
5.4 |
MEDIUM
Network
|
ibm
|
security_key_lifecycle_manager
|
IBM Security Key Lifecycle Manager 3.0.1 and 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4845
|
2024-11-21 14:33 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196809
|
5.3 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release information on the login dialog. This information could be used in further attack…
|
CWE-200
Information Exposure
|
CVE-2020-4908
|
2024-11-21 14:33 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196810
|
5.3 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the …
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-4907
|
2024-11-21 14:33 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|