|
194041
|
5.4 |
MEDIUM
Network
|
ibm
|
jazz_team_server
|
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote at…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-29865
|
2024-11-21 15:01 |
2022-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194042
|
6.5 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-…
|
NVD-CWE-noinfo
|
CVE-2021-29768
|
2024-11-21 15:01 |
2022-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194043
|
5.3 |
MEDIUM
Network
|
ibm
|
sterling_secure_proxy secure_external_authentication_server
|
IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associated with the host due to improper validation of cert…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-29726
|
2024-11-21 15:01 |
2022-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194044
|
7.2 |
HIGH
Network
|
ibm
|
maximo_asset_management maximo_application_suite
|
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remo…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2021-29854
|
2024-11-21 15:01 |
2022-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194045
|
6.8 |
MEDIUM
Physics
|
ibm
|
cloud_pak_for_business_automation
|
IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0.2 through V21.0.2-IF009, and V21.0.1 through V21.0.1-IF007) could allow a user…
|
NVD-CWE-noinfo
|
CVE-2021-29859
|
2024-11-21 15:01 |
2022-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194046
|
4.3 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's dashboard providing the dashboard ID of that user. IBM X-Force ID: 203030.
|
NVD-CWE-noinfo
|
CVE-2021-29776
|
2024-11-21 15:01 |
2022-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194047
|
4.3 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could have read access to to the 'Data Connections' page to which they don't have acces…
|
NVD-CWE-noinfo
|
CVE-2021-29824
|
2024-11-21 15:01 |
2022-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194048
|
6.5 |
MEDIUM
Network
|
ibm
|
engineering_requirements_quality_assistant_on-premises
|
IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of service. IBM X-Force ID: 207413.
|
NVD-CWE-noinfo
|
CVE-2021-29899
|
2024-11-21 15:01 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194049
|
9.8 |
CRITICAL
Network
|
pexip
|
infinity_connect
|
Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.
|
CWE-295
Improper Certificate Validation
|
CVE-2021-29656
|
2024-11-21 15:01 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194050
|
9.8 |
CRITICAL
Network
|
pexip
|
infinity_connect
|
Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2021-29655
|
2024-11-21 15:01 |
2022-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|