|
196841
|
6.5 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log files that could be read by an authenticatedl user. IB…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-4671
|
2024-11-21 14:33 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196842
|
4.3 |
MEDIUM
Network
|
ibm
|
sterling_file_gateway
|
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie val…
|
NVD-CWE-noinfo
|
CVE-2020-4665
|
2024-11-21 14:33 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196843
|
8.8 |
HIGH
Network
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which c…
|
CWE-89
SQL Injection
|
CVE-2020-4655
|
2024-11-21 14:33 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196844
|
8.8 |
HIGH
Network
|
ibm
|
sterling_file_gateway
|
IBM Sterling File Gateway 2.2.0.0 through 2.2.6.5 and 6.0.0.0 through 6.0.3.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta…
|
CWE-89
SQL Injection
|
CVE-2020-4647
|
2024-11-21 14:33 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196845
|
3.3 |
LOW
Local
|
ibm
|
infosphere_information_server
|
IBM InfoSphere Information Server 11.7 stores sensitive information in the browser's history that could be obtained by a user who has access to the same system. IBM X-Force ID: 190910.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-4886
|
2024-11-21 14:33 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196846
|
7.2 |
HIGH
Network
|
ibm
|
cognos_controller
|
A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Administration rights to the server where the application is installed, can escalate their privilege from …
|
NVD-CWE-noinfo
|
CVE-2020-4685
|
2024-11-21 14:33 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196847
|
5.4 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4760
|
2024-11-21 14:33 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196848
|
5.4 |
MEDIUM
Network
|
ibm
|
content_navigator
|
IBM Content Navigator 3.0CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pot…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4704
|
2024-11-21 14:33 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196849
|
7.8 |
HIGH
Local
|
ibm
|
filenet_content_manager
|
IBM FileNet Content Manager 5.5.4 and 5.5.5 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file con…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-4759
|
2024-11-21 14:33 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196850
|
4.8 |
MEDIUM
Adjacent
|
ibm
|
maximo_spatial_asset_management
|
IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tran…
|
CWE-352
Origin Validation Error
|
CVE-2020-4651
|
2024-11-21 14:33 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|