|
197061
|
8.1 |
HIGH
Network
|
ibm
|
curam_social_program_management
|
A HTTP Verb Tampering vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. By sending a specially-crafted request, an attacker could exploit this vulnerability to bypass sec…
|
CWE-287
Improper Authentication
|
CVE-2020-4779
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197062
|
7.5 |
HIGH
Network
|
ibm
|
curam_social_program_management
|
IBM Curam Social Program Management 7.0.9 and 7.0.10 uses MD5 algorithm for hashing token in a single instance which less safe than default SHA-256 cryptographic algorithm used throughout the Cúram …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-4778
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197063
|
7.5 |
HIGH
Network
|
ibm
|
curam_social_program_management
|
A path traversal vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could allow a remote attacker to traverse directories on the system. An attacker could send a spe…
|
CWE-22
Path Traversal
|
CVE-2020-4776
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197064
|
5.4 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnerability allows attackers to inject malicious scripts into web applications for t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4775
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197065
|
5.4 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling of user-supplied input. By sending a specially-crafted input, a remote attacker…
|
CWE-91
Blind XPath Injection
|
CVE-2020-4774
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197066
|
6.5 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a user to execute unwanted actions on the web applica…
|
CWE-352
Origin Validation Error
|
CVE-2020-4773
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197067
|
8.1 |
HIGH
Network
|
ibm
|
curam_social_program_management
|
An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit this vulnerability to expose sensitive informatio…
|
CWE-611
XXE
|
CVE-2020-4772
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197068
|
5.3 |
MEDIUM
Adjacent
|
ibm
|
security_access_manager security_verify_access
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-4699
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197069
|
5.3 |
MEDIUM
Adjacent
|
ibm
|
security_access_manager security_verify_access
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-4661
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197070
|
5.3 |
MEDIUM
Adjacent
|
ibm
|
security_access_manager security_verify_access
|
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-4660
|
2024-11-21 14:33 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|