|
197091
|
5.4 |
MEDIUM
Network
|
ibm
|
security_siteprotector_system
|
IBM Security SiteProtector System 3.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionalit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4140
|
2024-11-21 14:32 |
2021-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197092
|
5.9 |
MEDIUM
Network
|
ibm
|
qradar_network_security
|
IBM QRadar Network Security 5.4.0 and 5.5.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could e…
|
NVD-CWE-Other
|
CVE-2020-4160
|
2024-11-21 14:32 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197093
|
5.4 |
MEDIUM
Network
|
ibm
|
qradar_network_security
|
IBM QRadar Network Security 5.4.0 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended function…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4153
|
2024-11-21 14:32 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197094
|
5.9 |
MEDIUM
Network
|
ibm
|
qradar_network_security
|
IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtained using man in the middle techniques. IBM X-Force …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-4152
|
2024-11-21 14:32 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197095
|
8.4 |
HIGH
Local
|
vmware
|
vsphere_esxi fusion workstation
|
VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in NVM…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-3960
|
2024-11-21 14:32 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197096
|
7.8 |
HIGH
Local
|
ibm
|
security_verify_privilege_manager
|
IBM Security Secret Server (IBM Security Verify Privilege Manager 10.8.2 ) could allow a local user to execute code due to improper integrity checks. IBM X-Force ID: 184919.
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-4610
|
2024-11-21 14:32 |
2021-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197097
|
7.8 |
HIGH
Local
|
ibm
|
security_verify_privilege_manager
|
IBM Security Sevret Server (IBM Security Verify Privilege Manager 10.8.2) is vulnerable to a buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and execute …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-4609
|
2024-11-21 14:32 |
2021-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197098
|
8.8 |
HIGH
Network
|
ibm
|
rational_doors_next_generation rational_quality_manager collaborative_lifecycle_management engineering_test_management rational_engineering_lifecycle_manager engineering_lifecycle_mana…
|
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST A…
|
NVD-CWE-Other
|
CVE-2020-4495
|
2024-11-21 14:32 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197099
|
10.0 |
CRITICAL
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write fi…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2020-4561
|
2024-11-21 14:32 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197100
|
8.8 |
HIGH
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395.
|
CWE-79
Cross-site Scripting
|
CVE-2020-4520
|
2024-11-21 14:32 |
2021-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|