|
196861
|
6.0 |
MEDIUM
Local
|
ibm
|
spectrum_scale
|
IBM Spectrum Scale 5.0.4.1 through 5.1.0.3 could allow a local privileged user to overwrite files due to improper input validation. IBM X-Force ID: 192541.
|
CWE-20
Improper Input Validation
|
CVE-2020-4981
|
2024-11-21 14:33 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196862
|
7.5 |
HIGH
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_engineering_lifecycle_manager rhapsody_model_manager collaborative_lifecycle_management engineering_test_management engineeri…
|
IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4965
|
2024-11-21 14:33 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196863
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_engineering_lifecycle_manager rhapsody_model_manager collaborative_lifecycle_management engineering_test_management engineeri…
|
IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. …
|
NVD-CWE-noinfo
|
CVE-2020-4964
|
2024-11-21 14:33 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196864
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager rational_team_concert rational_engineering_lifecycle_manager rhapsody_model_manager collaborative_lifecycle_management engineering_test_management engineeri…
|
IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality …
|
CWE-79
Cross-site Scripting
|
CVE-2020-4920
|
2024-11-21 14:33 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196865
|
5.4 |
MEDIUM
Network
|
ibm
|
infosphere_information_server
|
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4997
|
2024-11-21 14:33 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196866
|
5.4 |
MEDIUM
Network
|
ibm
|
edge_application_manager
|
IBM Edge 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4792
|
2024-11-21 14:33 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196867
|
5.5 |
MEDIUM
Local
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-4944
|
2024-11-21 14:33 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196868
|
5.5 |
MEDIUM
Local
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-4884
|
2024-11-21 14:33 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196869
|
5.4 |
MEDIUM
Network
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 could allow an authenticated user to initiate a plugin or compare process resources that they should not have access to. IBM X-Force ID: 19029…
|
NVD-CWE-noinfo
|
CVE-2020-4848
|
2024-11-21 14:33 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196870
|
7.5 |
HIGH
Network
|
ibm
|
elastic_storage_server elastic_storage_system
|
IBM Elastic Storage System 6.0.0 through 6.0.1.2 and IBM Elastic Storage Server 5.3.0 through 5.3.6.2 could allow a remote attacker to cause a denial of service by sending malformed UDP requests. IBM…
|
NVD-CWE-noinfo
|
CVE-2020-5015
|
2024-11-21 14:33 |
2021-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|