|
194601
|
8.7 |
HIGH
Network
|
ibm netapp
|
db2 oncommand_insight
|
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-For…
|
CWE-863
Incorrect Authorization
|
CVE-2021-29678
|
2024-11-21 15:01 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194602
|
5.4 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-Force ID: 206212.
|
NVD-CWE-noinfo
|
CVE-2021-29867
|
2024-11-21 15:01 |
2021-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194603
|
8.8 |
HIGH
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted …
|
CWE-352
Origin Validation Error
|
CVE-2021-29756
|
2024-11-21 15:01 |
2021-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194604
|
5.3 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091
|
NVD-CWE-noinfo
|
CVE-2021-29719
|
2024-11-21 15:01 |
2021-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194605
|
6.5 |
MEDIUM
Network
|
ibm netapp
|
cognos_analytics oncommand_insight
|
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.
|
NVD-CWE-noinfo
|
CVE-2021-29716
|
2024-11-21 15:01 |
2021-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194606
|
4.3 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-29863
|
2024-11-21 15:01 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194607
|
6.1 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall…
|
CWE-79
Cross-site Scripting
|
CVE-2021-29849
|
2024-11-21 15:01 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194608
|
5.9 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in t…
|
NVD-CWE-Other
|
CVE-2021-29779
|
2024-11-21 15:01 |
2021-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194609
|
6.2 |
MEDIUM
Local
|
ibm
|
aix vios
|
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensitive information. IBM X-Force ID: 206085.
|
NVD-CWE-noinfo
|
CVE-2021-29861
|
2024-11-21 15:01 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194610
|
6.2 |
MEDIUM
Local
|
ibm
|
aix vios
|
IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the libc.a library to expose sensitive information. IBM X-Force ID: 206084.
|
NVD-CWE-noinfo
|
CVE-2021-29860
|
2024-11-21 15:01 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|