|
197101
|
8.1 |
HIGH
Network
|
ibm
|
spectrum_virtualize flashsystem_v5000_firmware flashsystem_v7200_firmware flashsystem_v9000_firmware flashsystem_v9100_firmware flashsystem_v9200_firmware san_volume_controller_firm…
|
IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges and perform actions they should not have access to. IBM X-Force ID: 186678.
|
NVD-CWE-noinfo
|
CVE-2020-4686
|
2024-11-21 14:33 |
2020-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197102
|
8.8 |
HIGH
Network
|
ibm
|
event_streams
|
IBM Event Streams 10.0.0 could allow an authenticated user to perform tasks to a schema due to improper authentication validation. IBM X-Force ID: 186233.
|
CWE-287
Improper Authentication
|
CVE-2020-4662
|
2024-11-21 14:33 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197103
|
5.5 |
MEDIUM
Local
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full control permissions, which could allow a local user to…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-4631
|
2024-11-21 14:33 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197104
|
5.4 |
MEDIUM
Network
|
ibm
|
planning_analytics_local
|
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended f…
|
CWE-79
Cross-site Scripting
|
CVE-2020-4645
|
2024-11-21 14:33 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197105
|
5.4 |
MEDIUM
Network
|
ibm
|
planning_analytics_local
|
IBM Planning Analytics Local 2.0.0 through 2.0.9.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker c…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-4644
|
2024-11-21 14:33 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197106
|
7.8 |
HIGH
Local
|
sonicwall
|
netextender
|
SonicWall NetExtender Windows client vulnerable to arbitrary file write vulnerability, this allows attacker to overwrite a DLL and execute code with the same privilege in the host operating system. T…
|
CWE-20
Improper Input Validation
|
CVE-2020-5131
|
2024-11-21 14:33 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197107
|
5.3 |
MEDIUM
Network
|
sonicwall
|
sonicos
|
SonicOS SSLVPN LDAP login request allows remote attackers to cause external service interaction (DNS) due to improper validation of the request. This vulnerability impact SonicOS version 6.5.4.4-44n …
|
CWE-20
Improper Input Validation
|
CVE-2020-5130
|
2024-11-21 14:33 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197108
|
6.5 |
MEDIUM
Network
|
traccar
|
traccar
|
Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By providing specially crafted input, an attacker can…
|
CWE-74
Injection
|
CVE-2020-5246
|
2024-11-21 14:33 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197109
|
6.5 |
MEDIUM
Network
|
dell
|
powerprotect_data_manager powerprotect_x400_firmware
|
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user ma…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-5356
|
2024-11-21 14:33 |
2020-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197110
|
8.8 |
HIGH
Network
|
dell
|
emc_data_protection_advisor
|
Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit this vulnerability to execute arbitrary commands on…
|
CWE-78
OS Command
|
CVE-2020-5352
|
2024-11-21 14:33 |
2020-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|