|
196811
|
9.8 |
CRITICAL
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, o…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-4690
|
2024-11-21 14:33 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196812
|
6.5 |
MEDIUM
Network
|
ibm
|
datapower_gateway
|
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user th…
|
CWE-352
Origin Validation Error
|
CVE-2020-4992
|
2024-11-21 14:33 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196813
|
5.4 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote atta…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4706
|
2024-11-21 14:33 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196814
|
5.4 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect 5.0.0.0 through 5.0.8.11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4707
|
2024-11-21 14:33 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196815
|
8.8 |
HIGH
Network
|
dell
|
emc_isilon_onefs emc_powerscale_onefs
|
The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allows access to an 'admin' home directory. An attacke…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-5353
|
2024-11-21 14:33 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196816
|
6.1 |
MEDIUM
Network
|
dell
|
emc_avamar_server
|
Dell EMC Avamar Server contains an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the vi…
|
CWE-601
Open Redirect
|
CVE-2020-5329
|
2024-11-21 14:33 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196817
|
7.5 |
HIGH
Network
|
dell
|
emc_data_protection_advisor
|
Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that is protected with a hard-coded password. A remote unauthenticated malicious us…
|
NVD-CWE-Other
|
CVE-2020-5351
|
2024-11-21 14:33 |
2021-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196818
|
9.8 |
CRITICAL
Network
|
dell
|
emc_integrated_data_protection_appliance_firmware emc_avamar_server
|
Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3,…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-5341
|
2024-11-21 14:33 |
2021-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196819
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_doors_next_generation rational_quality_manager rational_team_concert engineering_workflow_ma…
|
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5004
|
2024-11-21 14:33 |
2021-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196820
|
6.3 |
MEDIUM
Network
|
ibm
|
rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_doors_next_generation rational_quality_manager rational_team_concert engineering_workflow_ma…
|
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to netwo…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-4974
|
2024-11-21 14:33 |
2021-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|