|
197201
|
6.7 |
MEDIUM
Local
|
vmware
|
fusion
|
VMware Fusion (11.x) contains a privilege escalation vulnerability due to the way it allows configuring the system wide path. An attacker with normal user privileges may exploit this issue to trick a…
|
NVD-CWE-noinfo
|
CVE-2020-3980
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197202
|
8.2 |
HIGH
Network
|
ibm
|
maximo_for_life_sciences maximo_for_transportation control_desk maximo_for_oil_and_gas maximo_for_aviation maximo_for_utilities maximo_for_nuclear_power maximo_equipment_maintena…
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to conduct phishing attacks, using a tabnabbing attack. By persuading a victim to visit a specially-crafted Web site, a remot…
|
CWE-601
Open Redirect
|
CVE-2020-4409
|
2024-11-21 14:32 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197203
|
5.4 |
MEDIUM
Network
|
ibm
|
business_process_manager business_automation_workflow
|
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4530
|
2024-11-21 14:32 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197204
|
4.3 |
MEDIUM
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the we…
|
CWE-352
Origin Validation Error
|
CVE-2020-4526
|
2024-11-21 14:32 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197205
|
8.8 |
HIGH
Network
|
ibm
|
maximo_asset_management
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in Java. By sending specially-craf…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-4521
|
2024-11-21 14:32 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197206
|
3.3 |
LOW
Local
|
ibm
|
tivoli_business_service_manager
|
IBM Tivoli Business Service Manager 6.2.0.0 - 6.2.0.2 IF 1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 178247.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-4344
|
2024-11-21 14:32 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197207
|
5.4 |
MEDIUM
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4578
|
2024-11-21 14:32 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197208
|
5.4 |
MEDIUM
Network
|
ibm
|
business_automation_workflow business_process_manager
|
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4516
|
2024-11-21 14:32 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197209
|
7.8 |
HIGH
Local
|
ibm
|
aspera_connect
|
IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to o…
|
CWE-426
Untrusted Search Path
|
CVE-2020-4545
|
2024-11-21 14:32 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197210
|
6.5 |
MEDIUM
Network
|
ibm
|
api_connect
|
IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails that contain malicious URLs. IBM X-Force …
|
NVD-CWE-noinfo
|
CVE-2020-4337
|
2024-11-21 14:32 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|