|
197201
|
9.8 |
CRITICAL
Network
|
ibm
|
websphere_virtual_enterprise websphere_application_server
|
IBM WebSphere Application Server Network Deployment 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized object…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-4448
|
2024-11-21 14:32 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197202
|
7.3 |
HIGH
Network
|
ibm
|
mobile_foundation
|
IBM Worklight/MobileFoundation 8.0.0.0 does not properly invalidate session cookies when a user logs out of a session, which could allow another user to gain unauthorized access to a user's session. …
|
CWE-384
Session Fixation
|
CVE-2020-4229
|
2024-11-21 14:32 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197203
|
7.6 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information…
|
CWE-611
XXE
|
CVE-2020-4509
|
2024-11-21 14:32 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197204
|
9.8 |
CRITICAL
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-4193
|
2024-11-21 14:32 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197205
|
4.4 |
MEDIUM
Local
|
ibm
|
security_guardium
|
IBM Security Guardium 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174852.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4191
|
2024-11-21 14:32 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197206
|
6.1 |
MEDIUM
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4183
|
2024-11-21 14:32 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197207
|
6.5 |
MEDIUM
Adjacent
|
ibm
|
security_guardium
|
IBM Security Guardium 11.1 could allow an attacker on the same network to gain access to the Solr dashboard and cause a denial of service attack. IBM X-Force ID: 176997.
|
NVD-CWE-noinfo
|
CVE-2020-4307
|
2024-11-21 14:32 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197208
|
6.7 |
MEDIUM
Local
|
ibm
|
security_guardium
|
IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to extern…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-4190
|
2024-11-21 14:32 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197209
|
5.3 |
MEDIUM
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.1 could disclose sensitive information on the login page that could aid in further attacks against the system. IBM X-Force ID: 174805.
|
NVD-CWE-noinfo
|
CVE-2020-4187
|
2024-11-21 14:32 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197210
|
6.1 |
MEDIUM
Network
|
ibm
|
security_guardium
|
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4182
|
2024-11-21 14:32 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|